Cybersecurity report
Not dead yet: Dridex actors resume operation with new distribution and Shifu banking Trojan
Proofpoint, October 30, 2015. Dridex resurgence: Proofpoint's tracking of Dridex spam campaigns from sub-botnets 120, 121, 220 and 301 resuming within days of the 13 October 2015 takedown announcement.
- Source type
- Cybersecurity report
- Published
- October 30, 2015
- Research grade
- T2
- Used in entries
- 1
Bibliographic record
- Publisher
- Proofpoint
- Published
- October 30, 2015
- Source type
- Cybersecurity report
- Research grade
- Source grade T2
- Language
- English
- Official record
- Not an official publication
- What it supports
- Dridex resurgence: Proofpoint's tracking of Dridex spam campaigns from sub-botnets 120, 121, 220 and 301 resuming within days of the 13 October 2015 takedown announcement
- Dataset id
- src_proofpoint_dridex_not_dead_yet_2015
Research notes
- Attributed on the page to 'Proofpoint Staff'.
- The page's visible dateline reads October 30, 2015 and its schema.org datePublished is 2015-10-31T03:30:00Z, but its article:published_time meta tag says 2015-10-28T20:45:36-07:00. published_on follows the visible dateline.
How this source is used
Cited 1 time across 1 record type.
The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.
Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.
Cited by
Later activity
1 citation
Cited for activity recorded after the takedown.
-
Dridex campaigns resumed after the October 2015 disruptionTechnical evidence
Same operators, Dridex/Bugat/Cridex disruption