Zeus, also widely known as Zbot, is a Windows banking trojan and information-stealing malware family that became one of the most prominent financial malware strains in cybercrime. It is designed to steal confidential data, especially online banking credentials, and is commonly associated with credential theft through keylogging and form grabbing. The malware can also retrieve configuration data and updates after infection, enabling operators to adapt targeting and behavior over time.
Zeus has been repeatedly referenced as one of the most widespread banking malware families and has remained influential both as an active threat and as a codebase reused or emulated by later malware. It has been linked to broader banking-trojan ecosystems and is frequently discussed alongside families such as Gozi, Dridex, Ursnif, TrickBot, Qbot, and SpyEye. Its lineage also influenced later malware development, and derivatives or related families such as ZLoader have been described as downloader trojans for Zbot.
The malware targets Windows systems and has historically been delivered through multiple intrusion chains, including malicious spam campaigns, exploit-driven delivery, and secondary installation by other malware. Document-based exploitation and exploit kit activity have both been associated with delivery of Zbot-related payloads, and other botnets and downloaders have installed Zeus-family malware as follow-on payloads. Zeus infections have also been observed preceding deployment of additional malware, including ransomware.
Technically, Zeus is known for credential theft and user-input interception, and samples from the family have also been observed using code-injection techniques. Its operational role in financial cybercrime, prevalence across victim populations, and long-term reuse by criminal actors have made Zeus one of the defining banking trojan families of the Windows malware landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
<edit1 2013-01-25> ... It's also featuring CVE-2013-0422 since 13/01/13
Exploits: - CVE-2010-0188 (PDF LibTiff) ... CVE-2010-0188 : Impact EK - CVE-2012-0188 ... <edit1 2013-01-25> It seems it's featuring CVE-2011-0611 via CVE-2010-0188
<edit1 2013-01-25> It seems it's featuring CVE-2011-0611 via CVE-2010-0188 see post publications and Hendrik Adrian detailed analysis there.
Exploits: - CVE-2012-1723 (Java Applet Field Bytecode) ... CVE-2012-1723 : Impact EK - CVE-2012-1723 path (sames URLs) CVE-2012-1723 in one jar of Impact EK
Exploits: - CVE-2008-0655 (PDF colEmail) ... CVE-2008-0655 : Was not able to get infected with the proper configuration (Adobe Reader 8.1.1) ..don't know why.
Exploits: - CVE-2012-5076 (Java New Bytecode bypass) ... CVE-2012-5076 : Impact EK - CVE-2012-5076 Positive Path ... CVE-2012-5076 but seems implemented in a slightly different way than what we can see on other EK
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Firstly, we identify as financial the malware targeting users of financial services such as online banking, payment systems, e-money services, e-shops, and cryptocurrency services.
Facebook & VISA phishing campaign proposed by ZeuS ... New phishing campaign against Facebook led by Zeus ... ZeuS on IRS Scam remains actively exploited
These emails would contain a zip attachment that when opened would infect the computer. These zip files contain executables that are disguised as PDF files as they have a PDF icon and are typically named something like FORM_101513.exe or FORM_101513.pdf.exe.
Firstly, we identify as financial the malware targeting users of financial services such as online banking, payment systems, e-money services, e-shops, and cryptocurrency services.
It will then create one of the following autostart entries in the registry to start CryptoLocker when you login: KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker" ... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker"
Let’s look at one case across many families: Code Injection ... OpenProcess() on the target process ... VirtualAllocEx() ... WriteProcessMemory() ... CreateRemoteThread()
Firstly, we identify as financial the malware targeting users of financial services such as online banking, payment systems, e-money services, e-shops, and cryptocurrency services.
It will then create one of the following autostart entries in the registry to start CryptoLocker when you login: KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CryptoLocker" ... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "*CryptoLocker"
This time the traffic between the bot and the C2 is all the time encrypted by the same manner as the beacons: RC4 (key #2) + Visual Encrypt.
Zbot, also known as Zeus, is a trojan that steals information, such as banking credentials, using methods such as key-logging and form-grabbing.
Its capabilities include monitoring keystrokes, collecting video footage from the webcam, and uploading/executing follow-on malware.
The reports are geared towards banking theft. The reports could be of HTTP/S traffic, key logs, screenshots, cookies, passwords and mail.
Zbot, also known as Zeus, is a trojan that steals information, such as banking credentials, using methods such as key-logging and form-grabbing.
The malicious users who successfully used the PC-based ZeuS to steal personal user data for online banking systems and infect victims’ phones with ZitMo were thus able to overcome the last barrier of online banking security systems: the mTAN code.
Banking trojans and information stealers materialized as the second most prevalent type of cybercrime, with malware families like RedLine, Lumma, LokiBot, Negasteal, and ZBot taking up the top spots.
Zbot, also known as Zeus, is a trojan that steals information, such as banking credentials, using methods such as key-logging and form-grabbing.
Its capabilities include monitoring keystrokes, collecting video footage from the webcam, and uploading/executing follow-on malware.
The bot collects the process list, and allows you to launch SOCKS5/HVNC services via its backconnect server.
features: ... skidripped tor cnc from zbot ... custom tor cnc for onion that broadcasts loader server
It may also download configurations files and updates from the Internet.
382 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A banking trojan and information stealer identified as one of the top malware families prevalent in Asia and the South Pacific.
Banking trojan referenced as a payload distributed in Black Basta-linked activity.
Loader used post-initial-access to establish persistence, store encrypted config in registry, evade hooks by loading a fresh ntdll.dll, and inject into msedge.exe via process hollowing; used as a gateway for follow-on in-memory payloads and data theft.
Zbot is mentioned as one of the source malware families whose code EnemyBot derives from.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.