GameOver Zeus was a Russian- and Ukrainian-linked cybercriminal operation centered on a private, peer-to-peer evolution of the Zeus banking malware family, active from 2011 until its disruption in 2014. Also referred to as GOZ, Peer-to-Peer Zeus, P2P-ZeuS, ZeuS3, and internally associated with the "Business Club" crime ring, it combined large-scale banking fraud, botnet operations, malware distribution, and ransomware deployment. The operation has been tied to Evgeniy Bogachev, with reporting also linking members of the broader JabberZeus ecosystem and other Russian- and Ukrainian-speaking cybercriminal associates. The group primarily targeted corporate banking accounts and small to mid-sized businesses, using webinjects, man-in-the-browser techniques, token-grabbing, phishing support, and mule networks to conduct account takeover and fraudulent wire transfers. Its infrastructure was unusually resilient for its time, using a peer-to-peer command architecture, proxy layers, domain-generation mechanisms, signed updates, and layered backend administration to obscure operators and resist takedown. The botnet also supported delivery of additional malware and was used to distribute CryptoLocker, making GameOver Zeus one of the earliest major crimeware operations to combine banking trojan activity with ransomware monetization. Operational reporting describes a structured criminal enterprise with dual leadership, support personnel, suppliers, and numerous affiliates. The group relied on specialist providers for exploit kits, spam distribution, loaders, crypters, hosting, and money-mule management. It also conducted large-scale data theft from infected systems and used stolen information to support fraud operations. Documented capabilities include credential theft, exfiltration, persistence, initial access through exploit kits and spam, DDoS activity against financial institutions during fraud operations, and broad post-exploitation control of infected hosts. Although best known for financially motivated cybercrime, GameOver Zeus infrastructure was also observed being used to search victim systems for intelligence- and government-related information associated with Georgia, Turkey, and Ukraine, indicating at least some espionage-oriented tasking alongside its core criminal activity. Law-enforcement and private-sector disruption efforts in 2014 targeted its peer-to-peer network, proxy infrastructure, and domain-generation mechanisms, significantly degrading the operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime operation/botnet described as pioneering a service model (botnet-as-a-service) and enabling ransomware deployment (CryptoLocker), influencing later CaaS-style crimeware ecosystems.
Named criminal operation associated in the article with Evgeniy Bogachev; mentioned as linked background to the JabberZeus ecosystem through the malware author.
Botnet operation referenced as the distribution mechanism for CryptoLocker; attributed in the text to a Russian cybercriminal (distribution infrastructure for ransomware).
Financially motivated cybercrime group operating the GameOver ZeuS botnet for corporate banking fraud, credential theft, mule-account enabled wire fraud, and later CryptoLocker deployment; the content also describes espionage-oriented tasking against government and intelligence-related targets in Georgia, Turkey, Ukraine, and OPEC-related interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.