GameOver Zeus, also known as Peer-to-Peer Zeus or P2P Zeus, is a Windows banking trojan and botnet that emerged around September 2011 as a private evolution of the Zeus malware family. Its principal purpose is to steal banking and other credentials, enabling account takeover and fraudulent wire transfers from businesses and consumers. The botnet also supported distributed denial-of-service attacks and the installation of additional malware, notably CryptoLocker ransomware during 2013 and 2014.
Unlike earlier Zeus variants that relied primarily on centralized infrastructure, GameOver Zeus relayed commands and updates through a decentralized peer-to-peer network of infected computers. It combined this network with command-and-control proxy layers and a domain generation algorithm, making disruption more difficult. Proxy nodes routed commands and stolen data between infected systems and backend infrastructure. Distribution included spam campaigns, Upatre downloader infections, and the Blackhole and Magnitude exploit kits. Some campaigns redirected Chrome users to fraudulent browser-update pages to induce installation rather than attempting browser exploitation.
The operation was associated with a predominantly Russian and Ukrainian cybercriminal network known as the Business Club. U.S. authorities charged Evgeniy Bogachev in 2014 with offenses related to its administration. GameOver Zeus infected an estimated 500,000 to one million Windows computers worldwide and caused more than $100 million in losses. In June 2014, Operation Tovar disrupted its infrastructure through coordinated international law-enforcement and industry action involving peer-list manipulation, proxy-layer intervention, domain redirection, and sinkholing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gameover Zeus – Bad Guys and Backends ... Gameover Zeus September 2011 – June 2014 Private builds, introduced P2P protocol
GameOver ZeuS, GOZ, peer-to-peer ZeuS, P2P-ZeuS and ZeuS3 are analogous to each other and refer to a ZeuS based malware family, which was active in the wild from September 2011 till May 2014.
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
the samples were downloaded from a compromised website located in the United States... Gameover Zeus has also been distributed by the Blackhole and Magnitude exploit kits.
Infection Method Blackhole Exploit Kit • Specific configuration for Gameover Zeus
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
During our research, we found a large amount of search queries which were executed on the victim systems. The search queries consisted of a number of keywords... focused on locating “government classified” material
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
even in its early days, the malware could receive dynamic configuration files, use web injections to steal money
The principal purpose of the botnet is to capture banking credentials from infected computers.
Espionage ... Targeting government and intelligence agencies ... foreign intelligence ... counter intelligence ... top secret
The token-grabber attack in peer-to-peer ZeuS... The victim would see a normal, or almost normal, login page of their bank... During the victim being on hold, the browser would continuously poll the backend to check if new questions were available to ask the victim.
Dridex has been able to escape justice for so long by hiding its main command-and-control (C&C) servers behind proxying layers.
It uses a tiered, decentralized system of intermediary proxies and strong encryption to hide the location of servers that the botnet masters use to control the crime machine.
By early 2015, Dridex implemented a kind of P2P network... some peers (supernodes) had access to the C&C and forwarded requests from other network nodes to it.
The Necurs botnet has historically been used to deliver a torrent of other high profile cyber threats to the world, including the GameOver Zeus and Dridex banking trojans, Locky ransomware and, more recently, the banking trojan turned all purpose cybercrime-as-a-service, Trickbot.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Zeus descendant using peer-to-peer command infrastructure for banking fraud and credential theft. Also distributed CryptoLocker. International authorities disrupted it in June 2014.
A decentralized peer-to-peer botnet cited for its resilient architecture. Authorities disrupted its network and seized key infrastructure in 2014.
Uses infected machines to relay commands over peer-to-peer channels, reducing dependence on a single centralized server or domain.
Mentioned only as a prior botnet disruption that used peer-list manipulation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.