Zeus, also known as Zbot, is a Windows banking trojan that emerged in the late 2000s and became one of the most widespread and influential malware families in cybercrime. It is designed primarily to steal online banking and other sensitive credentials by capturing passwords and account data, hijacking browser sessions, altering web forms, redirecting victims to fraudulent pages, and injecting malicious content into banking websites. Zeus is also associated with man-in-the-browser style fraud, botnet-based operations, and large-scale financial theft campaigns against businesses, banks, municipalities, and other organizations.
Zeus commonly infected Microsoft Windows systems and spread through spam and phishing campaigns as well as drive-by download activity. Once installed, it communicated with command-and-control infrastructure to exfiltrate stolen information and receive configuration updates. Variants and related operations used botnets and money-mule networks to monetize stolen banking credentials through unauthorized transfers. The malware family was heavily used by organized cybercrime groups, including the JabberZeus ecosystem, and U.S. criminal cases tied Zeus operations to Maksim Yakubets and associated conspirators.
The Zeus codebase had an outsized impact on the banking-malware landscape. Its source code leak in 2011 enabled extensive reuse, adaptation, and derivative development, contributing to successor and descendant families such as Citadel, Gameover Zeus, Panda Banker, Chthonic, and Zloader. Zeus also influenced later web-injection frameworks adopted by other banking trojans. Technical reporting has noted Zeus-related command-and-control communications protected with self-signed TLS certificates, including anomalous certificate fields. Zeus remains historically significant as a foundational banking trojan whose architecture, fraud techniques, and leaked source code shaped a generation of financially motivated malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploit:Java/CVE-2012-1723 ... File type: ZIP Tags: exploit zip cve-2012-1723 ... Microsoft Exploit:Java/CVE-2012-1723!generic
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ukrainian national Vyacheslav Igorevich Penchukov, one of the heads of the notorious JabberZeus cybercrime gang, has pleaded guilty to charges related to his leadership roles in the Zeus and IcedID malware groups.
M. Bogatchev a créé le code malveillant ZeuS (alias Zbot). ZeuS est loué en tant que malware-as-a-service à d’autres groupes cybercriminels.
해당 악성 파일은 빌드타임(KST) 기준으로 2020년 11월 10일 제작됐습니다. 그리고 64비트 DLL 형식을 가지고 있으며 익스포트 함수명이 'ut_zeus(x64).dll' 입니다... 악성 모듈 제작자는 '제우스(zeus)' 이름을 지정해 여러차례 변종을 제작한 바 있는데, 2020년 07월 10일 제작된 32비트 변종은 익스포트 함수명이 'ut_zeus(x86).dll' 입니다.
Bogatchev ... created the malware-as-a-service Zeus (alias Zbot) to produce new variants with uncovered features.
During 1H2010, the criminals instead emphasized the Avalanche infrastructure as a major distribution point for the notorious Zeus Trojan. Zeus is a sophisticated piece of malware that is in the hands of many different e-criminals.
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
The domain can also be set up to impersonate the intended domain for instance to host a phishing page, serve malware...
These are kits that are stitched into hacked or malicious Web sites, so that all visiting browsers are checked for a variety of insecure, outdated plugins, from Flash to Java to Adobe Reader.
Browsers that are found vulnerable will be handed a Trojan downloader that fetches Reveton and most likely a copy of the password-stealing Citadel/ZeuS Trojan.
We describe how to reverse engineer the two binaries and compare the obfuscation and anti-debugging techniques used by them.
Local data, server requests, and the configuration file are RC4 encrypted with the key of your choice.
The malware masquerades as a PDF document to lure an unsuspecting user into opening the file.
Intercept of WinAPI by means of splicing... Always used WinAPI from wininet.dll for this interception.
access and exfiltrate sensitive information, harvest credentials, or deploy a wide variety of malware.
Rewrote FTP/POP3 sniffer, improved detection of logins, introduced support for IPv6-addresses.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
Yakubets and his co-conspirators allegedly infected thousands of business computers with malicious software that captured passwords, account numbers, and other information necessary to log into online banking accounts
...and inject arbitrary content when victims visited banking Web sites.
Added grabber passwords for the following FTP-Client... Removed TAN-grabber... Changed behavior of the certificates grabbers.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
Yakubets and his co-conspirators allegedly infected thousands of business computers with malicious software that captured passwords, account numbers, and other information necessary to log into online banking accounts
...and inject arbitrary content when victims visited banking Web sites.
To achieve this, the bytes in network packets are packaged in BinStorage structures that are sent over HTTPS. Each byte in the BinStorage structure is XOR'd by the previous byte and then additionally encrypted with RC4.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
Microsoft security center - disable update notifications, disable antimalware scan... Windows firewall settings - Allow exceptions, disable notifications, disable the firewall... Windows Defender & AntiMalware settings - Exclude malware processes, injected system processes and certain file types from scanning
398 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
The malware strain is linked to the Russian cyber criminal group Evil Corp, the group behind the Zeus and Dridex malware and associated with several large-scale ransomware and money laundering operations.
The malware is attributed to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with numerous ransomware and money-laundering operations.
SocGholish is linked to the Russian cyber‑criminal group Evil Corp. This group has previously been responsible for Zeus and Dridex malware and is also associated with several large‑scale ransomware and money‑laundering operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.