GameOver Zeus, also known as Peer-to-Peer Zeus or GOZ, was a major Zeus-derived banking malware family active from about September 2011 to mid-2014. It targeted Microsoft Windows systems and combined credential theft with resilient botnet functionality through a decentralized peer-to-peer command-and-control architecture, distinguishing it from earlier centrally managed Zeus variants. The malware was primarily used to steal banking and other online account credentials, including through man-in-the-browser and browser-injection techniques, and to support fraudulent wire transfers from victim organizations. Infected hosts were enrolled into a large global botnet that was also used for spam operations and distributed denial-of-service attacks, particularly in support of financial theft operations.
GameOver Zeus is closely associated with the criminal ecosystem attributed to Evgeniy Bogachev and Russian- and Ukrainian-speaking cybercriminal operators. Reporting has linked the botnet to losses exceeding $100 million and to infection counts ranging from hundreds of thousands to roughly one million systems worldwide. The malware used encrypted peer-to-peer communications, proxy layers, and a domain generation algorithm to improve resilience and complicate disruption. Peers could relay configuration updates, binary updates, stolen data, and command traffic, while the architecture reduced single points of failure.
The malware was distributed through spam and phishing campaigns and was also delivered via exploit kits and other malware delivery botnets. It was historically propagated by services and malware ecosystems including Necurs, Cutwail, and Upatre. GameOver Zeus also served as a delivery platform for additional payloads, most notably CryptoLocker ransomware, which was deployed onto already infected systems as part of the operators’ monetization model. Beyond banking fraud, some reporting has described the botnet as being leveraged for espionage-oriented collection against government and intelligence-related targets in countries neighboring Russia.
GameOver Zeus was the subject of the multinational Operation Tovar disruption in 2014, which combined legal, technical, and international law-enforcement actions to interfere with its peer-to-peer infrastructure and related ransomware operations. Its legacy is significant in the evolution of cybercrime, particularly in advancing large-scale, modular, and service-oriented banking malware operations that influenced later threats such as Dridex and other financially motivated botnet ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gameover Zeus – Bad Guys and Backends ... Gameover Zeus September 2011 – June 2014 Private builds, introduced P2P protocol
GameOver ZeuS, GOZ, peer-to-peer ZeuS, P2P-ZeuS and ZeuS3 are analogous to each other and refer to a ZeuS based malware family, which was active in the wild from September 2011 till May 2014.
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
the samples were downloaded from a compromised website located in the United States... Gameover Zeus has also been distributed by the Blackhole and Magnitude exploit kits.
Infection Method Blackhole Exploit Kit • Specific configuration for Gameover Zeus
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
During our research, we found a large amount of search queries which were executed on the victim systems. The search queries consisted of a number of keywords... focused on locating “government classified” material
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
even in its early days, the malware could receive dynamic configuration files, use web injections to steal money
The principal purpose of the botnet is to capture banking credentials from infected computers.
Espionage ... Targeting government and intelligence agencies ... foreign intelligence ... counter intelligence ... top secret
The token-grabber attack in peer-to-peer ZeuS... The victim would see a normal, or almost normal, login page of their bank... During the victim being on hold, the browser would continuously poll the backend to check if new questions were available to ask the victim.
Dridex has been able to escape justice for so long by hiding its main command-and-control (C&C) servers behind proxying layers.
It uses a tiered, decentralized system of intermediary proxies and strong encryption to hide the location of servers that the botnet masters use to control the crime machine.
By early 2015, Dridex implemented a kind of P2P network... some peers (supernodes) had access to the C&C and forwarded requests from other network nodes to it.
The Necurs botnet has historically been used to deliver a torrent of other high profile cyber threats to the world, including the GameOver Zeus and Dridex banking trojans, Locky ransomware and, more recently, the banking trojan turned all purpose cybercrime-as-a-service, Trickbot.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a peer-to-peer banking trojan/botnet used for banking fraud, malware distribution, and intelligence collection.
Malware used as a primary distribution mechanism for CryptoLocker; it was downloaded by Upatre and then installed additional malware families including CryptoLocker.
Banking malware and botnet operated as a service model for other threat actors, cited here as pioneering cybercrime-as-a-service and deployment of follow-on ransomware.
A Zeus-derived banking trojan botnet that uses DGA-based C2 communications to evade disruption and steal banking credentials and funds from victims’ accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.