Gameover Zeus is a peer-to-peer banking trojan derived from the Zeus malware lineage and best known for combining credential theft with resilient decentralized command-and-control. It primarily targeted Windows systems and was part of the early generation of P2P botnets that shifted Zeus-style financial malware away from purely centralized infrastructure. The malware is associated with theft of online banking credentials and related financial fraud operations. Its peer-to-peer architecture also made the botnet more robust against takedown efforts and enabled infected hosts to exchange peer information and other operational data. Gameover has additionally been documented as a P2P botnet whose protocol behavior could be abused in amplification-based distributed denial-of-service scenarios. In security literature, Gameover is commonly referenced alongside other Zeus-derived banking malware and early Windows-focused P2P botnets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
ZeroAccess P2P bot offers three message types as part of its command-and-control communication. Sality is a malware downloader and bots can thus exchange URL lists of files that bots should install on the infected PC... In the Gameover P2P bot, a banking trojan, we leverage the peer list and proxy list exchange mechanism
In distributed reflective denial-of-service (DRDoS) attacks, adversaries send requests to public servers (e.g., open recursive DNS resolvers) and spoof the IP address of a victim. These servers, in turn, flood the victim with valid responses and – unknowingly – exhaust its bandwidth.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early Windows-targeting P2P botnet referenced in the historical overview.
Zeus-derived malware/botnet referenced only in historical context.
Mentioned only as another malware family using hashing-based DGA techniques for comparison.
P2P banking trojan botnet that exchanges peer and proxy lists and can be abused for DRDoS amplification; bots also provide proxies used to upload stolen banking credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.