The Business Club, also tracked as GOLD EVERGREEN, was a Russian cybercriminal group associated with operation of the Zeus and Gameover Zeus botnets until international law-enforcement disruption in May 2014. It is part of the broader Eastern European financially motivated cybercrime ecosystem and is notable as a predecessor environment from which later operators linked to Evil Corp emerged. The group is associated with large-scale banking-trojan and botnet activity centered on Zeus and Gameover Zeus. Its operations supported credential theft and broader criminal monetization through malware-enabled fraud. Reporting also links the ecosystem around GOLD EVERGREEN to use of Pony, also known as Fareit or Siplog, a long-running loader and stealer used to harvest credentials and deliver additional malware. In that context, associated tradecraft included phishing-based delivery, use of compromised websites and fake software installers, anti-analysis checks, persistence mechanisms, process injection or hollowing, command-and-control communications, and theft of credentials and configuration data from browsers, FTP clients, and email software. GOLD EVERGREEN is also significant for its relationship to later financially motivated groups. Operators later associated with GOLD DRAKE, better known as Evil Corp, have been described as former affiliates of GOLD EVERGREEN, indicating continuity between the Zeus/Gameover Zeus criminal ecosystem and subsequent Dridex- and ransomware-linked operations. The actor is best understood as a major Russian cybercrime group focused on credential theft, botnet operations, and malware-enabled financial crime rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal group historically associated with operating Zeus and Gameover Zeus botnets; referenced as an antecedent/affiliate relationship (GOLD DRAKE operators described as former affiliates).
Cybercriminal group historically associated with operating Zeus and Gameover Zeus botnets; referenced as an antecedent/affiliate relationship (GOLD DRAKE operators described as former affiliates).
Named as a more organized criminal threat group observed using the Pony/Fareit malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.