Dyre, also known as Dyreza and Dyzap, was a Windows banking Trojan active from 2014 to 2016 that targeted major online banking services and became known for man-in-the-browser credential theft. It was associated with financially motivated cybercrime operations and caused substantial losses to banking institutions, particularly in the United States. Dyre is widely regarded as a predecessor and design influence for later banking malware such as TrickBot.
The malware focused on stealing banking credentials and related sensitive information by hooking into browser activity and intercepting user interactions with targeted financial websites. It supported exfiltration of stolen data to command-and-control infrastructure and could identify the current user and local network configuration on compromised hosts, indicating built-in host profiling and victim targeting logic. Dyre also decrypted embedded resources needed for victim targeting and operational execution.
On infected systems, Dyre used process injection to load modules into other processes and employed scheduled tasks for persistence, including repeatedly launching itself through the Windows Task Scheduler. Reporting also links Dyre operators and related crimeware ecosystems to exploit-enabled privilege escalation through vulnerabilities such as CVE-2013-3660 and CVE-2015-0057.
Dyre was commonly delivered through spam and phishing campaigns carrying malicious Microsoft Office documents and attachments. In notable campaigns, operators used the Gophe spambot and Upatre as part of multi-stage email delivery chains designed to evade detection through randomized attachments and embedded payload staging. After installation, Dyre could also download and run Gophe to send further spam from infected hosts, supporting botnet-style propagation and large-scale malspam operations.
The malware occupied an important place in the evolution of banking trojans, bridging earlier Zeus-era tradecraft and later modular crimeware platforms. Its operators were reportedly disrupted by arrests, and its decline was followed by the rise of successor malware families, especially TrickBot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2015-0057 Classification: 1-Day Basic Description: Use-After-Free in win32k!xxxEnableWndSBArrows Used by the following malware families: Dyre, Evotob | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit ... CVE-2015-0057 ... a month later this exploit was used by the Dyre Banking Trojan.
Our Ramnit sample exploits both CVE-2013-3660 (by PlayBit) and CVE-2014-4113 (using the same exploit code originally found as a 0-Day).
CVE-2013-3660 Classification: 1-Day Basic Description: Uninitialized kernel pointer in EPATHOBJ::pprFlattenRec Used by the following malware families: Dyre, Ramnit | CVE-2013-3660 ... Used by the following malware families: Dyre, Ramnit ... CVE-2015-0057 ... a month later this exploit was used by the Dyre Banking Trojan.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The original exploit for CVE-2014-4113 was part of an exploit framework in which the API passes a command-line argument, and that command is executed as SYSTEM. As that wasn’t the original API for PlayBit’s exploit, some adjustments were made and PlayBit’s exploits were re-adjusted to receive a command-line argument to be executed once elevated.
A trojan is any type of malicious program disguised as a legitimate one.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
While the variant analyzed included a fallback mechanism of reaching out to icanhazip.com in the event STUN didn’t work
Since JA3 detects the client application, it doesn’t matter if malware uses DGA (Domain Generation Algorithms), or different IPs for each C2 host, or even if the malware uses Twitter for C2, JA3 can detect the malware itself based on how it communicates rather than what it communicates to. | JA3 allows us to detect these applications, malware families, and pen testing tools, regardless of their destination, Command and Control (C2) IPs, or SSL certificates.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
This is useful for identifying domains that were previously part of domain generation algorithms (DGAs) or otherwise used for various malware operations like command and control (C2).
this post focuses on the misuse of STUN by malware... It is our belief that this trending of STUN capabilities in malware supports two goals for attackers... Hide in plain sight : Given a popular service and/or protocol, there is a higher likelihood that malware that utilizes similar communications can achieve equivalent success in its misuse, as it is allowed through the same security controls.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
84 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier banking trojan whose infrastructure takedown is presented as the backdrop to TrickBot’s emergence; previously targeted customers of many U.S. and U.K. banks.
Dyre is mentioned as the predecessor to TrickBot and as a banking-fraud-focused malware family used for comparison and lineage context.
Mentioned only as historical context for developer use of minilzo/LZO-era techniques.
Banking trojan referenced as previously using the STUN protocol to determine the public IP address of infected systems, with icanhazip.com as a fallback.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.