APT / THREAT GROUP

IceCube

2
aliases
Last seen:Jul 15, 2026

Intelligence Profile

According to Proofpoint, IceCube is a JavaScript-based stealer likely developed with the assistance of a large language model, targeting Roundcube webmail instances. It escapes the webmail's iFrame context via DOM traversal to access the full document and the authentication session, then exfiltrates usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data (such as language, screen size, and form field values) via HTTP POST to its command-and-control server. The malware is heavily commented with well-marked execution phases, and incorporates self-cleanup routines, "fallbacks" for failed exploitation steps, and "deferred triggers" that hook browser events such as tab changes, mouse leaving the window, and the logout button to re-attempt exploitation. After successful server-side exploitation, it destroys both user and malware-initiated sessions to remove forensic evidence from the Roundcube server.

Threat Analysis

IceCube is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

js.icecubeIceCube

External Intelligence

Malpedia: js.icecube

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.