Report: IcedID malware developer allegedly faked his own death to evade the FBI

THE BRIEF
Risky Business News reports that a developer of the IcedID malware allegedly faked his own death in an attempt to evade the FBI. The account appears in the publication’s 13 February 2026 Risky Bulletin, which presents the incident alongside reports that Apple patched a zero-day used in a targeted attack, the Tianfu Cup had quietly returned, and researchers had identified what the bulletin describes as the first malicious Outlook add-in. The supplied material does not provide the developer’s name, explain how the alleged deception was carried out, or describe any resulting arrests, charges, victims, or operational impact. It also does not provide technical indicators for IcedID or the Outlook add-in. Organizations should therefore treat the item as a source-reported development and avoid inferring more than the bulletin states. For defenders, the main relevance is the reminder that malware investigations can involve evasion efforts, while the bulletin’s other topics may warrant separate review through authoritative security updates.
WHY IT MATTERS
Reports that a malware developer allegedly faked his own death to avoid the FBI highlight the potential difficulty of cybercrime investigations and the importance of maintaining reliable evidence. The supplied report does not establish whether the alleged deception succeeded, whether anyone was charged, or whether it changed IcedID activity. Still, organizations tracking IcedID should ensure their monitoring, evidence preservation, and escalation processes are ready to support investigations without relying on unverified claims.
WHO SHOULD CARE
Security operations, incident response, threat intelligence, and legal teams tracking IcedID activity or cybercrime investigations should care. Organizations following Apple and Outlook security developments may also want to review the bulletin’s other reported items separately.
WHAT TO DO NOW
- Check whether internal threat-intelligence or incident-response records contain any suspected IcedID activity requiring further review.
- Review relevant endpoint, network, and identity telemetry using the organization’s approved IcedID detections and investigative procedures.
- Preserve logs and other available evidence if suspected IcedID activity or related investigation evidence is identified.
- Track follow-up reporting and authoritative security advisories, treating the IcedID account and the bulletin’s other topics as separate items to verify.