{
  "family": "dridex",
  "sample_count": 59,
  "category": "banking_trojan",
  "description": "Dridex is a prolific banking trojan that, per MITRE ATT&CK, first appeared in 2014. By December 2019 the US Treasury estimated Dridex had infected computers across hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking trojan (also known as Cridex). It is distributed mainly through malicious email attachments, and its operators have also been linked to delivering ransomware.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Dridex",
    "Bugat v5",
    "Cridex"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Dridex?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A prolific banking trojan, first seen in 2014, that steals banking credentials and financial information."
      }
    },
    {
      "@type": "Question",
      "name": "How much damage has Dridex caused?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "By December 2019 the US Treasury estimated infections across hundreds of financial institutions in over 40 countries and more than $100 million in theft."
      }
    },
    {
      "@type": "Question",
      "name": "Where did Dridex come from?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It was built from the source code of the earlier Bugat banking trojan, also known as Cridex."
      }
    },
    {
      "@type": "Question",
      "name": "How is Dridex delivered?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Most often through phishing emails carrying malicious Office documents with macros."
      }
    },
    {
      "@type": "Question",
      "name": "Is Dridex linked to ransomware?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Its operators have been associated with delivering ransomware as a follow-on payload in some campaigns."
      }
    },
    {
      "@type": "Question",
      "name": "How can I reduce exposure to Dridex?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Disable macros from untrusted documents, be cautious with email attachments, use multi-factor authentication on financial accounts, and keep systems patched."
      }
    },
    {
      "@type": "Question",
      "name": "Where is the authoritative reference?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE ATT&CK's Dridex entry (S0384), linked on this page."
      }
    }
  ],
  "faq_count": 7,
  "mitre_attack": [
    "T1185",
    "T1056.004",
    "T1055.012",
    "T1021.002",
    "T1071.001",
    "T1547.001"
  ],
  "cisa_advisory": "https://www.cisa.gov/news-events/alerts/2019/12/13/dridex-malware",
  "last_updated": "2026-06-09",
  "sources": [
    {
      "name": "MITRE ATT&CK: Dridex (S0384)",
      "url": "https://attack.mitre.org/software/S0384"
    }
  ],
  "mitre_url": "https://attack.mitre.org/software/S0384",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}