Home/Threat Actor/IcedID / BokBot Operators (Lunar Spider)
Threat Actor

IcedID / BokBot Operators (Lunar Spider)

icedid_operators · russia_speaking_organized_cybercrime · active since 2017-04

IcedID / BokBot Operators (canonical CrowdStrike naming Lunar Spider.

Mandiant UNC2198 for ransomware-affiliate- operations cluster.

Microsoft Storm-0464 partial overlap; IBM X-Force ITG14) is a Russia-speaking organized cyber- criminal cluster financially-motivated, active publicly since April 2017, one of the operationally-most-significant banking-trojan-to-loader cluster transitions in modern cyber-threat-intelligence history.

originated as a banking trojan distributed by Emotet malspam targeting US-bank- customer and US-telecommunications-vendor-customer credentials, with sophisticated tradecraft including steganography-based configuration concealment (IcedID configuration hidden inside PNG image files), man-in-the- browser web-injection tradecraft, and anti-VM/anti-sandbox evasion.

operationally pivoted to loader-as-a-service (Download-as-a-Service / DaaS) model in 2019-2020 with IcedID acting both as banking trojan and malware loader for follow-on ransomware payload delivery.

operates via paid distribution-affiliate partnership with TA551 / UNC2420 / Shathak (US DOJ court filings disclosed in March 2026 Ilya Angelov sentencing memorandum documented over US$1 million paid by IcedID operators to Angelov's TA551 group for botnet access in late 2019 / early 2020)

IcedID infections served as primary initial-access vector for sequential ransomware-affiliate operations including Maze (2020), Egregor (late 2020 - early 2021), Conti (2021, peak operational tempo following Conti Leaks documentation), and post-Conti diversification across Quantum Locker / BlackCat / Royal / XingLocker (2022-2025)

March 2026 US DOJ Angelov sentencing (2 years imprisonment + US$100,000 fine, Tolyatti, Russia origin) operationally confirmed the Russia-based operational basing of the TA551 distribution- affiliate cluster and is one of the few publicly-documented US-government criminal prosecutions of an identified operator within the broader IcedID-TA551 ecosystem.

russia_speaking_organized_cybercrime confidence: high 20 aliases MITRE ATT&CK G0046 ↗

Profile

IcedID / BokBot Operators (canonical CrowdStrike naming Lunar Spider for the developer-operator cluster.

Mandiant UNC2198 for the IcedID-to-ransomware affiliate-operations cluster; Microsoft Storm-0464 partial overlap.

IBM X-Force ITG14; malware family also referred to as BokBot or Bok Bot) is a Russia-speaking organized cyber-criminal cluster financially- motivated, active publicly since April 2017, one of the operationally-most-significant banking-trojan-to-loader cluster transitions in modern cyber-threat-intelligence history. The cluster's signature malware family (IcedID / BokBot) is operationally cluster-defining, the cluster is consistently identified across industry vendor reporting by the signature malware family. The cluster operates under the loader-as-a-service (also referred to in industry analysis as Download-as-a-Service / DaaS) operational model from approximately 2019-2020 onward, with IcedID acting as both a banking-credential-theft trojan (signature 2017-2019 operational era) and a malware loader supporting follow-on payload delivery (signature 2020-present operational era). The cluster operates in close operational partnership with distribution-affiliate TA551 (Shathak / G0127 / Gold Cabin / Hive0106 / Mario Kart / Monster Libra / Mandiant UNC2420), a separate but operationally-linked malspam-distribution cluster operationally based in Russia and Eastern Europe.

Operational phases of the cluster's longitudinal history: (1) BANKING TROJAN ERA (April 2017
  • 2019). Foundational operational era as a banking trojan distributed via Emotet malspam infections, focused on US-bank-customer and US- telecommunications-vendor-customer credential theft. The cluster's earliest variants implemented sophisticated tradecraft including: man-in-the-browser web-injection tradecraft for capturing online-banking credentials, web- session cookies, and credit-card data; steganography tradecraft hiding IcedID configuration data inside PNG images (operationally distinctive among 2017-era banking trojans); anti-VM, anti-sandbox, and anti-debug evasion capability; modular plugin architecture enabling dynamic capability loading. IcedID's earliest distribution relationship, being distributed BY Emotet, would operationally invert in subsequent years as IcedID itself became a loader for follow-on payloads. (2) LOADER-AS-A-SERVICE OPERATIONAL PIVOT (2019-2020). The cluster operationally pivoted from banking-trojan-only operations toward the loader-as-a-service operational model. The pivot was driven by two factors: (a) the broader two- factor-authentication adoption across financial-institution customer accounts that made banking-credential-only theft operationally less monetizable per compromised host; (b) the broader Russia-speaking-organized-cybercrime industry shift toward ransomware-as-a-service operations that increased operational demand for reliable initial-access delivery into target organizations. IcedID infections began monetizing through access-resale to ransomware affiliates as a parallel revenue stream alongside continued banking- credential-theft operations. (3) TA551 / UNC2420 DISTRIBUTION PARTNERSHIP ERA (Late 2019.
  • August 2021). Per US Department of Justice court filings disclosed in the March 2026 Ilya Angelov sentencing memorandum, the IcedID operators paid Angelov's group (TA551 / UNC2420 / Shathak) over US$1 million to acquire access to the TA551 botnet in late 2019 or early 2020 for IcedID distribution operations. The partnership operationally established TA551 as the primary distribution channel for IcedID across the 2020-2021 era. TA551's signature reply- chain-hijacking phishing email tradecraft with password- protected ZIP archive attachments + password-in-message-body delivery was operationally devastating for IcedID distribution (password-protected attachments evaded many email-security platform scanning mechanisms; reply-chain-hijacking lures dramatically improved social-engineering effectiveness). Per Mandiant February 2021 reporting, TA551 deployed the MOUSEISLAND macro downloader as initial-stage execution followed by PHOTOLOADER secondary-stage downloader, which ultimately installed IcedID. (4) FLAGSHIP RANSOMWARE-AFFILIATE ECOSYSTEM ERA (2020-2022). IcedID infections served as a primary initial-access vector for multiple ransomware-as-a-service operations including Maze (2020, curated separately as maze_ransomware.yaml), Egregor (late 2020.
  • early 2021, Maze successor), Conti (2021, curated separately as wizard_spider_conti.yaml), Quantum Locker, REvil, and XingLocker. Mandiant's UNC2198 tracking documented the IcedID-to-ransomware-operations affiliate cluster as operationally distinct from but operationally-coordinated with the IcedID developer cluster (Lunar Spider) and the distribution affiliate (TA551 / UNC2420). The Conti Leaks of February 2022 subsequently provided detailed operational documentation of the IcedID- Conti operational partnership across the 2021 operational period. (5) POST-EMOTET-TAKEDOWN AND POST-2022 DIVERSIFICATION (Q1 2021.
  • present). Following the Europol/Eurojust January 27, 2021 Emotet international takedown, TA551 operationally stepped in to fill some of the malspam-distribution void left by Emotet's disruption, and IcedID distribution via TA551 reached peak operational scale during this period. Following Conti's operational shutdown in mid-2022, IcedID operational affiliate relationships diversified across multiple successor ransomware-as-a-service operations including Quantum Locker, BlackCat / ALPHV, Royal / BlackSuit, REvil successor operations, and XingLocker. The cluster has undergone multiple operational variants in 2022-2023 including IcedID Forked (lite functionality variant), updated initial-loader-v3 components, and revised C2 communication protocols.
Signature operational tradecraft includes
  • Steganography-based configuration concealment: IcedID operationally hides its configuration data inside PNG image files (signature operational tradecraft preserved across multiple operational eras and IcedID major versions).
  • Multi-component installation chain: IcedID installation operationally involves successful deployment of multiple software components before execution of the main IcedID module (initial-stage loader.
  • gzip loader.
  • main module DLL.
  • persistence loader).
  • Sophisticated anti-analysis tradecraft: anti-VM, anti- sandbox, anti-debug detection routines operationally consistent across IcedID major versions.
  • Man-in-the-browser web-injection tradecraft: signature banking-trojan-era capability for capturing online-banking credentials, web-session cookies, and credit-card data through browser-function hijacking.
  • Distribution via paid-service relationship with TA551 / UNC2420 / Shathak: signature operational pattern of operating as a developer-operator cluster while paying a separate distribution-affiliate cluster (TA551) for malspam- distribution operational services, operationally distinguishes IcedID operators from competing loader-as-a- service operators (Qakbot operators, Emotet operators) that operationally maintain in-house distribution capability.
  • Cobalt Strike Beacon as primary post-compromise framework: operationally consistent with broader Russia-speaking- organized-cybercrime affiliate-operations tooling patterns.
  • Multi-RaaS-affiliate sequential operational relationships: Maze.
  • Egregor.
  • Conti.
  • Quantum / BlackCat / Royal / XingLocker, operationally similar to the multi-ransomware- affiliate operational pattern observed for FIN8 and Vice Society / Vanilla Tempest (separately curated in this corpus). The cluster is operationally significant as one of the modern era's most operationally consequential banking-trojan- to-loader transition clusters, with sustained operational tempo across approximately 9 years of tracked operations. The IcedID-TA551 paid-service operational partnership is one of the best-publicly-documented examples of specialized service-provider operational relationships within the broader Russia-speaking-organized-cybercrime malware ecosystem. The cluster fills the modern banking-trojan-to- loader cluster cell in this corpus, complementing the broader Tier-2.5 loader-as-a-service coverage (qakbot_operators.yaml, emotet_operators.yaml) and the broader Tier-2 ransomware coverage (maze_ransomware.yaml, wizard_spider_conti.yaml, alphv_blackcat.yaml, and others).

Aliases

20
lunar spiderlunar-spiderlunarspidericedidiceidbokbotbok_botbok botunc2198unc-2198unc2420unc-2420storm-0464itg14itg-14icedid operators (lunar spider)icedid_operatorsbokbot_operatorsicedid operatorsbokbot operators

MITRE ATT&CK aliases

5
Additional names MITRE lists for G0046.
FIN7GOLD NIAGARACarbon SpiderELBRUSSangria Tempest

Notable Campaigns

9
2026US DOJ Ilya Angelov TA551 Co-Manager Sentencing (March 2026)
2022-presentPost-2022 Affiliate-Relationship Diversification and Continued Operations (2022-Present)
2021Conti Ransomware Affiliate Chain (2021)
2021Emotet Takedown Void-Filling Distribution Surge (Q1 2021)
2020-2021Maze + Egregor Ransomware Affiliate Chain (2020 - Early 2021)
2020TA551 Switches Primary Payload to IcedID (Q2 2020)
2019-2020Loader-as-a-Service Operational Pivot (2019-2020)
2019-2020TA551 / UNC2420 / Shathak Distribution Partnership Established (Late 2019 - Early 2020)
2017IcedID Banking Trojan Operational Emergence (April 2017)

Attribution & Reporting

Attributed by
CrowdStrikeMandiantGoogle Cloud Threat IntelligenceProofpointMicrosoft Threat Intelligence CenterIBM X-ForceEclecticIQ Threat ResearchCisco TalosSecureWorks Counter Threat UnitTrend MicroSymantec / Broadcom Threat Hunter TeamESETKaspersky GReATCybereasonRed CanaryF5 LabsCheck Point ResearchVolexitySOC PrimeSANS Internet Storm CenterUS FBIUS Department of JusticeFrench CERT (ANSSI)Malware-Traffic-Analysis.net
Key reporting
reportCrowdStrike: Lunar Spider Operational Profile, IcedID/BokBot developer-operator (multiple years)
reportMandiant: Melting UNC2198 IcedID to Ransomware Operations (February 2021), canonical Mandiant IcedID-to-ransomware affiliate-cluster disclosure
reportMandiant: TA551 / UNC2420 / Shathak Operational Tracking, distribution-affiliate cluster, MOUSEISLAND + PHOTOLOADER tooling attribution
reportProofpoint: TA551 (Shathak) Operational Profile (multiple years)
reportEclecticIQ Threat Research: A Look into Banking Trojan IcedID's Installation Process (September 2021)
reportF5 Labs: How The IcedID Banking Trojan Exploits Pandemic (March 2021)
reportCisco Talos: IcedID Continued Operational Tracking
reportSecureWorks Counter Threat Unit: GOLD CABIN Operational Profile (Mandiant overlap with TA551)
reportTrend Micro: TA551 Distributes New ICEDID Malware
reportSOC Prime: TA551 Hackers Spread IcedID Trojan in a New Wave of Malspam Campaign
reportIBM X-Force: ITG14 Operational Tracking (IcedID developer-operator cluster)
reportRed Canary: IcedID + TA551 Detection Engineering Profile (multiple years)
reportMicrosoft Threat Intelligence: Storm-0464 + IcedID Tracking
reportCheck Point Research: IcedID Evolution and 2023 Operations
reportElastic Security Labs: Thawing the Permafrost of IcedID (multiple years)
reportESET: IcedID Threat Analysis
reportKaspersky GReAT: IcedID Banking Trojan Analysis
reportCybereason: IcedID Operational Profile
reportSANS Internet Storm Center: TA551 (Shathak) Pushes IcedID (Bokbot) Diary Series, Brad Duncan tracking
reportMalware-Traffic-Analysis.net: TA551 (Shathak) Word Docs Push IcedID (Bokbot) Continued Sample-Sharing Research
reportMalpedia Malware Profile: Win.IcedID
reportMalpedia Actor Profile: TA551
reportMITRE ATT&CK Software S0483, IcedID
reportMITRE ATT&CK Group G0127, TA551
reportUS Department of Justice: Russian National Ilya Angelov Sentenced for Managing TA551 Cybercriminal Group (March 2026), canonical US-government prosecution

Operational

State sponsor

Russia-speaking organized cyber-criminal cluster, financially- motivated, tracked under canonical CrowdStrike naming Lunar Spider as the developer-operator cluster behind the IcedID / BokBot malware family. The cluster has been consistently tracked as organized cybercrime operating from Russia-speaking or Eastern European jurisdictions across CrowdStrike, Mandiant, Proofpoint, Microsoft, IBM X-Force, EclecticIQ, Cisco Talos, SecureWorks, Trend Micro, Symantec, ESET, Kaspersky, and partner industry vendor tracking. No formal government cybersecurity attribution to a specific state actor has been asserted.

the cluster has not been linked to state intelligence services. The cluster operates under the loader-as-a-service (also referred to in industry analysis as Download-as-a- Service / DaaS) operational model, with IcedID acting as both a banking-credential-theft trojan (signature 2017-2019 operational era) and a malware loader supporting follow-on payload delivery (signature 2020-present operational era). The cluster operates in close operational partnership with distribution-affiliate TA551 (Shathak / G0127 / Gold Cabin / Hive0106 / Mario Kart / Monster Libra / Mandiant UNC2420) , a separate but operationally-linked malspam-distribution cluster that has historically distributed IcedID, Qakbot, Ursnif/Gozi ISFB, Valak, BumbleBee, and Emotet payloads on behalf of paying customers. TA551 distributes IcedID for Lunar Spider operators among other customers. The March 2026 US Department of Justice prosecution of Ilya Angelov (aliases "milan" and "okart"), sentenced to 2 years and fined US$100,000 for co-managing the TA551 cybercriminal group between 2017 and 2021, operationally confirmed the Russia-based operational basing of the TA551 distribution affiliate ("of Tolyatti, Russia" per DOJ filings). The DOJ filings further documented that IcedID operators paid TA551 over US$1 million to acquire botnet access in late 2019 or early 2020 for ransomware distribution operations, with the partnership lasting until approximately August 2021. IcedID operators (Lunar Spider) and TA551 (Mandiant UNC2420) are operationally distinct clusters with a documented paid- service operational relationship.

The cluster's operational partnership relationships with the broader Russia-speaking- organized-cybercrime ransomware ecosystem are operationally significant: IcedID infections served as a primary initial- access vector for Maze ransomware (2020), Egregor ransomware (late 2020
  • early 2021), Conti ransomware (2021), Quantum Locker, REvil, XingLocker, and broader Wizard Spider ecosystem operations. The Wizard Spider operations are curated separately as wizard_spider_conti.yaml; Maze is curated as maze_ransomware.yaml.
Motivations
banking_credential_theft_historical_2017_2019, financial_fraud, loader_as_a_service_revenue, download_as_a_service_daas_model, access_resale_to_ransomware_affiliates, credential_and_session_cookie_exfiltration
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MAZE RANSOMWAREMOUSEISLANDSHARPHOUND
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin