Dyre was a financially motivated cybercrime operation centered on a banking trojan that emerged in the mid-2010s and is widely regarded as one of the major successors to earlier crimeware-as-a-service ecosystems associated with GameOver Zeus. It is commonly discussed alongside Dridex as one of two prominent criminal models formed by former participants or customers of the Business Club ecosystem. Dyre specialized in banking credential theft and online banking fraud, using web-inject-style techniques and related credential-harvesting tradecraft against financial institutions and their customers. Reporting also links remnants of the Dyre operation to the formation of TrickBot after law-enforcement pressure disrupted Dyre in 2016, making Dyre an important predecessor in the lineage of later modular banking malware and enterprise-focused crimeware platforms. Dyre is associated with financially driven cybercrime rather than state-directed espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crimeware/botnet operation described as advancing botnet solutions and influencing TrickBot’s backend integration and design.
A cybercrime team mentioned as a former Business Club offshoot whose backend ideas and work later accumulated in TrickBot.
A predecessor criminal group whose remnants assembled to form Trickbot in 2015 after arrests disrupted Dyre leadership.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.