{"id":1933,"date":"2018-05-30T20:10:11","date_gmt":"2018-05-30T20:10:11","guid":{"rendered":"https:\/\/kasperskycontenthub.com\/threatpost\/?p=132392"},"modified":"2018-05-30T20:10:11","modified_gmt":"2018-05-30T20:10:11","slug":"botnet-operators-team-up-to-leverage-icedid-trickbot-trojans","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/","title":{"rendered":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans"},"content":{"rendered":"<div class=\"media_block\"><\/div>\n<div><img decoding=\"async\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/31\/2018\/02\/06221624\/malware-img-55.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>The botnet operators behind two infamous banking trojans have banded together to gouge victims of cash in a tricky collaborative scheme.<\/p>\n<p>Flashpoint analysts, who highlighted the collaboration in a Wednesday <a href=\"https:\/\/www.flashpoint-intel.com\/blog\/trickbot-icedid-collaborate-increase-impact\/\">report<\/a>, said that the operators behind the\u00a0 IcedID and TrickBot trojans appear to be targeting banking victims in a dual threat \u2014 and sharing the profit.<\/p>\n<p>Researchers first discovered the collaboration while studying the IcedID malware \u2013 they quickly realized that computers infected with IcedID were also downloading the other piece of malware, Trickbot.<\/p>\n<p>\u201cWhy would IcedID, which is commercial banking malware, download another commercial banking malware from the same ecosystem? We decided to look into it; we found it unusual because groups compete for a limited number of victims,\u201d Vitali Kremez, director of research at Flashpoint, told Threatpost.\u201dWhile looking at that, we realized that IcedID and Trickbot were working together \u2013 not necessarily from the malware development side, but from the operations side.\u201d<\/p>\n<p>Malware strains typically butt heads over victims\u2019 data, particularly in a hyper-competitive market like banking; for example, the SpyEye malware has been seen to uninstall the similar Zeus trojan upon infecting machines, Kremez said.<\/p>\n<p><a href=\"https:\/\/threatpost.com\/trickbot-malware-now-targets-us-banks\/126976\/\">Trickbot<\/a> has made its mark as a trojan responsible for man-in-the-browser attacks since mid-2016. The malware has targeted financial institutions, and\u00a0is a successor to the\u00a0<a href=\"https:\/\/threatpost.com\/us-cert-warns-of-dyre-banking-trojan\/109056\/\">Dyre banking Trojan,<\/a> sharing many of the same attributes. The trojan\u00a0leverages multiple modules, including leaked exploits, and targets victims for various malicious activities, such as cryptocurrency mining and ATO operations.<\/p>\n<p>The <a href=\"https:\/\/threatpost.com\/new-icedid-trojan-targets-us-banks\/128851\/\">IcedID Trojan<\/a>\u00a0meanwhile was spotted in 2017 by researchers at IBM\u2019s X-Force Research team. They said the trojan has several standout techniques and procedures; most notably for this situation the ability to\u00a0create proxies that are used to steal credentials for a host of websites (mainly in financial services). The local proxy intercepts traffic and uses a web inject that steals login data from the victim.<\/p>\n<p>Kremez said it appears that IcedID is sent directly as spam via email, and the piece of malware then acts as a downloader that installs TrickBot, which in turn installs other modules on victims\u2019 machines.<\/p>\n<p>The two combined forces use an array of methods and tools to then steal banking credentials from the victims, including token grabbers, redirection attacks and web injects.<\/p>\n<p>\u201cThe attacks are complex\u2026there are other modules at the operators\u2019 disposal that allow them to have deep coverage of a victim\u2019s machine and expand the breadth and scope of an attack, thereby allowing them to derive additional potential sources of profit from a successful compromise,\u201d according to Flashpoint.<\/p>\n<p>The double-edged threat is not only bringing a new force of tools to the table; from an operations standpoint, the collaboration pulls in an extended network of fraud operators who can carry efficient account takeover operations. \u201cOne of the main things behind the Trickbot-IcedID collaboration are the human operators behind this,\u201d said Kremez.<\/p>\n<p><strong>Complex Collaboration<\/strong><\/p>\n<p>Flashpoint said it \u201cassesses with high confidence\u201d that a head of operations likely oversees a complex network of fraudsters who connect back to machines infected by the two trojans. This head is the botmaster, who operates the command and control of botnets for remote process execution.<\/p>\n<p>Meanwhile, the bad actors who make up the extensive network likely know each other only by aliases and are specialists within their respective domains, Kremez told Threatpost.<\/p>\n<p>\u201cLinguistic analysis and an investigation into TrickBot and IcedID botnet operations reveals that the campaign involving a botnet belongs to a small group that commissions or buys the banking malware, manages the flow of infections, makes payments to the project\u2019s affiliates (traffic herders, webmasters, mule handlers), and receives the laundered proceeds,\u201d Flashpoint said in the report.<\/p>\n<p>Essentially,when the victims log in to the banking page of interest on an infected system, the botmaster accepts XMPP or Jabber notifications via the \u201cjabber_on\u201d field in the backend.<\/p>\n<p>The combined malware operation also has the ability to carry out account checking (or\u00a0credential stuffing), which determines the value of a victim\u2019s machine and\u00a0their access \u2014 so the bad actors can leverage higher-value targets for network\u00a0penetration and use other compromised targets for things like cryptocurrency mining.<\/p>\n<p>The botmaster then is able to extract information consisting of the victim\u2019s login credentials, answers to the secret questions and email address from the logs, and then passes that information to an affiliate who manages real-world operations.<\/p>\n<p>Meanwhile, mules use that information to open bank accounts in the geographic location of the victim and at the same financial institution. They in turn receive fraudulent account clearing house (ACH) and wire transfers into their account and then forward the proceeds to the botnet owner or an intermediary.<\/p>\n<p>\u201cBased on the close collaboration between TrickBot and IcedID operators and their shared backend infrastructure, it is likely that the operators will continue to closely collaborate on cashing out stolen accounts,\u201d Flashpoint noted. Additional details about the breadth of attacks and the amount of money stolen at this point are unknown.<\/p>\n<p>Kremez said he expects more botnet operators to begin a similar collaboration scheme in the future: \u201cThis is only the beginning,\u201d he said. \u201cIt\u2019s getting harder and harder to commit fraud when it comes to banking\u2026 and I think this is where the collaboration will really start to come in.\u201d<\/p>\n<p>READ MORE <a href=\"https:\/\/threatpost.com\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/132392\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The botnet operators behind two infamous trojans have banded together to gouge victims in a costly scheme. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":1934,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[3],"tags":[412,927,928,28,929,916,19],"class_list":["post-1933","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threatpost","tag-botnet","tag-icedid","tag-joint-operation","tag-malware","tag-trickbot","tag-trojan","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-30T20:10:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"710\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans\",\"datePublished\":\"2018-05-30T20:10:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/\"},\"wordCount\":888,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg\",\"keywords\":[\"botnet\",\"IcedID\",\"joint operation\",\"Malware\",\"TrickBot\",\"Trojan\",\"Vulnerabilities\"],\"articleSection\":[\"Threatpost\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/\",\"name\":\"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg\",\"datePublished\":\"2018-05-30T20:10:11+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg\",\"width\":710,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"botnet\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/botnet\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/","og_locale":"en_US","og_type":"article","og_title":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-30T20:10:11+00:00","og_image":[{"width":710,"height":400,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans","datePublished":"2018-05-30T20:10:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/"},"wordCount":888,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg","keywords":["botnet","IcedID","joint operation","Malware","TrickBot","Trojan","Vulnerabilities"],"articleSection":["Threatpost"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/","url":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/","name":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg","datePublished":"2018-05-30T20:10:11+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans.jpg","width":710,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/botnet-operators-team-up-to-leverage-icedid-trickbot-trojans\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"botnet","item":"https:\/\/www.threatshub.org\/blog\/tag\/botnet\/"},{"@type":"ListItem","position":3,"name":"Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=1933"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/1933\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/1934"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=1933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=1933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=1933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}