Gozi is a long-running eCrime malware operation centered on a banking trojan designed to steal online banking credentials and facilitate fraudulent transfers from victim accounts. The malware infected more than one million computers between 2007 and 2013. US authorities charged three core figures tied to the operation: Nikita Kuzmin, identified as the original creator; Deniss Calovskis, associated with development of web injects used to impersonate banking login pages; and Romanian national Mihai Ionut Paunescu, also known as "Virus," who was accused of operating a bulletproof hosting service that protected and scaled Gozi infrastructure. Authorities alleged that Paunescu played a major role in the botnet’s growth, particularly around the Gozi 2.0 period. Gozi is best known as a credential-stealing banking trojan rather than a ransomware or destructive actor. Its activity focused on harvesting e-banking credentials and enabling theft from financial accounts. The operation relied on resilient criminal infrastructure and protected hosting to shield command-and-control systems from disruption. After the Gozi source code leaked in 2013, it became the basis for multiple successor and derivative malware families, including Gozi ISFB, Neverquest, Ursnif, Vawtrak, Rovnix, and other related banking trojans, extending its influence across the broader cybercrime ecosystem. Separate reporting also notes overlaps between Gozi-associated tooling or loader services and other major eCrime ecosystems, including Maze, Zloader, and TrickBot, indicating that Gozi-linked operators or services have intersected with broader organized crimeware activity. A referenced subgroup or cluster, Gozi ConfCrew, has been associated with loader-service overlap in such reporting. The dominant motivation is financial gain through credential theft and banking fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an overlapping crimeware ecosystem connection through shared certificate-chain pivots and loader keys tied to the profiled Maze affiliate.
Referenced as part of the affiliate's overlap with other major eCrime malware ecosystems, including shared certificate-chain and loader-key pivots.
A cybercriminal group responsible for creating, operating, and expanding the Gozi banking trojan botnet, using protected hosting and web injects to steal online banking credentials and funds from victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.