Description
[Dridex](https://attack.mitre.org/software/S0384) is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated [Dridex](https://attack.mitre.org/software/S0384) had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. [Dridex](https://attack.mitre.org/software/S0384) was created from the source code of the Bugat banking Trojan (also known as Cridex).(Citation: Dell Dridex Oct 2015)(Citation: Kaspersky Dridex May 2017)(Citation: Treasury EvilCorp Dec 2019)
External References
Techniques Used by This Malware
- T1027 — Obfuscated Files or Information
- T1053.005 — Scheduled Task
- T1071.001 — Web Protocols
- T1082 — System Information Discovery
- T1090 — Proxy
- T1090.003 — Multi-hop Proxy
- T1106 — Native API
- T1185 — Browser Session Hijacking
- T1204.002 — Malicious File
- T1218.010 — Regsvr32
- T1219 — Remote Access Tools
- T1518 — Software Discovery
- T1573.001 — Symmetric Cryptography
- T1573.002 — Asymmetric Cryptography
- T1574.001 — DLL