Gozi is a long-running eCrime threat actor and malware ecosystem centered on the Gozi banking trojan, a credential-stealing malware family used to harvest online banking credentials and facilitate theft from victim accounts. The operation was active at scale from at least 2007 through 2013, during which the botnet was reported to have infected more than one million computers. Gozi is associated with financially motivated cybercrime and with a core group that included Nikita Kuzmin, identified as the original creator of the trojan; Deniss Calovskis, associated with development of web injects used to impersonate banking login pages; and Mihai Ionut Paunescu, a Romanian national alleged to have provided protected infrastructure and operational support through a bulletproof hosting service. That hosting support was described as instrumental in shielding command-and-control infrastructure and enabling the botnet’s growth. Gozi’s primary tradecraft centered on credential theft and post-compromise fraud against online banking users. The malware family became especially influential after its source code leaked, seeding numerous successor and derivative strains including Gozi ISFB and related banking trojans. Gozi has also been linked in broader crimeware overlap analysis to other major eCrime ecosystems, including Zloader, TrickBot, and ransomware affiliate activity, reflecting shared tooling, loader-service relationships, and criminal collaboration across malware operations. A subgroup or operator cluster referred to as Gozi ConfCrew has been associated with loader-service activity in later overlap reporting. Gozi is best characterized as a financially motivated cybercriminal operation rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an overlapping crimeware ecosystem connection through shared certificate-chain pivots and loader keys tied to the profiled Maze affiliate.
Referenced as part of the affiliate's overlap with other major eCrime malware ecosystems, including shared certificate-chain and loader-key pivots.
A cybercriminal group responsible for creating, operating, and expanding the Gozi banking trojan botnet, using protected hosting and web injects to steal online banking credentials and funds from victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.