diff --git a/galaxy.html b/galaxy.html
index 4acc3f2..0d68c31 100755
--- a/galaxy.html
+++ b/galaxy.html
@@ -9961,6 +9961,29 @@ Banker is a cluster galaxy available in JSON format at
+ According to X-Force research, the new banking Trojan emerged in the wild in September 2017, when its first test campaigns were launched. Our researchers noted that IcedID has a modular malicious code with modern banking Trojan capabilities comparable to malware such as the Zeus Trojan. At this time, the malware targets banks, payment card providers, mobile services providers, payroll, webmail and e-commerce sites in the U.S. Two major banks in the U.K. are also on the target list the malware fetches.IcedID
+
Links |
+
https://www.bleepingcomputer.com/news/security/new-icedid-banking-trojan-discovered/ |
+
https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/ |
+
PROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation for several years. Truvasys has been involved in several attack campaigns, where it has masqueraded as one of server common computer utilities, including WinUtils, TrueCrypt, WinRAR, or SanDisk. In each of the campaigns, Truvasys malware evolved with additional features—this shows a close relationship between the activity groups behind the campaigns and the developers of the malware.