SpyEye is a Windows banking trojan and botnet malware family first observed in 2009 and widely used for online banking fraud and credential theft. It targets web browsers to steal authentication data through keylogging and form grabbing, and it supports man-in-the-browser style abuse of online banking sessions, including initiating fraudulent transactions while victims are logged in. SpyEye was also known for a feature intended to remove Zeus from infected systems, reflecting direct competition within the banking-malware ecosystem.
The malware family collects and exfiltrates credentials and other financial data to attacker-controlled infrastructure. Reported variants and kit capabilities include downloading updates or additional files, persistence on infected hosts, and rootkit-style concealment through API hooking and related defense-evasion measures. SpyEye kits were sold and operated as crimeware, enabling botnet management and modular monetization. One documented monetization module automated fraudulent online purchases using stolen payment-card data, illustrating how operators converted harvested financial information into cash.
SpyEye primarily targets Windows systems and popular web browsers used for online banking and other account access. Its activity expanded beyond simple credential theft to broader financial fraud, with targeting reported across numerous financial institutions and countries. The malware was hosted and distributed through criminal infrastructure alongside other major banking malware families, and it was associated with large-scale attacks against companies and financial institutions.
SpyEye has strong historical ties to Eastern European cybercrime. Aleksandr Andreevich Panin and Hamza Bendelladj were sentenced in 2016 for developing and distributing the malware. SpyEye is frequently discussed alongside Zeus, Citadel, and related banking trojans because of overlapping techniques, shared criminal markets, and later source-code leakage that influenced the wider crimeware landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
the defendants pleaded guilty to conspiring to engage in a Racketeer Influenced Corrupt Organization (RICO) arising from their providing “bulletproof hosting” services between 2008 and 2015, which were used by cybercriminals to distribute malware and attack financial institutions and victims throughout the United States.
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
The domain can also be set up to impersonate the intended domain for instance to host a phishing page, serve malware...
Using the handle Gribodemon here, the software developer scoffed, saying he had secretly built in a backdoor that would allow him to seize remote control over PCs infected with his bot.
A trojan is any type of malicious program disguised as a legitimate one.
Specifically, Harderman says he wants to turn the guts of the Trojan into a rootkit, and to build additional functionality on top, in the form of modular plug-ins.
We describe how to reverse engineer the two binaries and compare the obfuscation and anti-debugging techniques used by them.
So SpyEye’s authors are now trying to mimic — albeit in an automated way — how a real person would navigate a website.
SpyEye made headlines this year when investigators discovered it automatically searched for and removed ZeuS from infected PCs before installing itself.
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
SpyEye targeted Windows users running some of the most popular web browsers. It logged keystrokes and used form grabbing techniques to steal users' credentials.
Webinjects: Used for speeding up report gathering. With Webinjects you can change the content of a website and ask for more information.
The group rented IP addresses, servers, and domains to cybercriminal clients who employed this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
SpyEye targeted Windows users running some of the most popular web browsers. It logged keystrokes and used form grabbing techniques to steal users' credentials.
Webinjects: Used for speeding up report gathering. With Webinjects you can change the content of a website and ask for more information.
SpyEye is actually a botnet with a network of command-and-control servers hosted around the world.
The malware communicated with command-and-control servers; one which was controlled by Bendelladj and located in Georgia.
The billinghammer module also is set up to evade anti-fraud controls at the online software stores, by funneling each transaction through a SpyEye-infected system whose Internet address traces back to a geographic location that approximates the cardholder’s street addresss.
macros embedded within the Word document will execute, facilitating the download and executing the malware from an attacker-controlled server... PowerShell script, which downloads and executes the malware
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware bot/family discussed in the paper, with emphasis on reverse engineering, obfuscation, anti-debugging, and its inter-process communication with ZeuS.
Banking trojan malware used to gain access to victims’ computers, form botnets, and steal banking credentials for fraud.
Named as another banking trojan whose operators used the suspect's bulletproof hosting services.
Banking crimeware mentioned as background context in relation to rumors of a merger with ZeuS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.