Zeus, also known as Zbot or ZeuS, is a Windows banking trojan that emerged in 2007 and became one of the foundational malware families in modern financially motivated cybercrime. It was designed to steal online banking credentials and other sensitive financial information from infected systems, and it was widely used in account-takeover fraud against small and midsized businesses, financial institutions, and online service users in the United States, Europe, and elsewhere. Zeus is strongly associated with Russian-speaking cybercriminal ecosystems and has been linked to operators and affiliates later tied to Evil Corp and to major fraud crews such as the JabberZeuS gang. Variants including Gameover Zeus expanded the threat through more resilient botnet operations and large-scale financial theft.
Zeus is best known for credential theft from online banking sessions, including capture of account numbers, passwords, PINs, and related authentication data. Reported Zeus capabilities also include keylogging and browser-focused interception techniques such as form grabbing and man-in-the-browser style memory injection to harvest credentials before or during submission. In criminal operations, Zeus infections were used to enable fraudulent ACH and wire transfers, often supported by money-mule networks. Some Zeus-based operations also sold access to infected machines and harvested data to other criminals, making the malware part of a broader cybercrime service ecosystem.
Distribution historically relied heavily on phishing and malspam campaigns, including spam messages carrying malicious attachments or links to compromised websites. Large phishing infrastructures such as Avalanche were used to distribute Zeus variants at scale. The malware was also embedded in targeted banking-themed email lures aimed at business victims. In later criminal workflows, Zeus-derived tooling and successor variants were integrated into broader botnet and fraud operations.
Zeus had outsized strategic impact because its source code leaked in 2011, accelerating the development of successor malware and influencing the wider infostealer and banking-trojan landscape. Security reporting has repeatedly identified Zeus as an early precursor to many later credential-stealing families. The family also intersected with SpyEye, including efforts by criminal developers to merge or transition capabilities between the two malware lines. Overall, Zeus remains one of the most consequential banking trojans due to its role in industrializing credential theft, online banking fraud, and malware-as-a-service style cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware strain is linked to the Russian cyber criminal group Evil Corp, the group behind the Zeus and Dridex malware and associated with several large-scale ransomware and money laundering operations.
During 1H2010, the criminals instead emphasized the Avalanche infrastructure as a major distribution point for the notorious Zeus Trojan. Zeus is a sophisticated piece of malware that is in the hands of many different e-criminals.
These days it seems more often involved in sending emails that try to trick recipients into opening malware-laden attachments, most often variants of the ZeuS and SpyEye trojans.
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
The JabberZeuS Crew, the Business Club, and other crime rings collectively pocketed over $200 million from U.S. and U.K. financial institutions using Evgeniy Bogachev’s ZeuS banking trojan...
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
31 distinct techniques documented for this family, organized by ATT&CK tactic.
In November 2010, Panin allegedly received the source code and rights to sell Zeus from Evginy Bogachev, a/k/a Slavik, and incorporated many components of Zeus into SpyEye.
According to data recorded by Abuse.ch, some of the domains Microsoft seized appear to belong to legitimate businesses whose sites were compromised and used to host components of the malware infrastructure.
These lures took victims to “drive-by download” sites, where the criminals infected vulnerable machines.
"Avalanche" is the name given to the world's most prolific phishing gang and to the infrastructure it uses to host phishing sites. And this is the group that has shifted additional resources to the creation of spoof sites and spam lures that distributed the very latest, most malignant Zeus variants.
Specifically, Harderman says he wants to turn the guts of the Trojan into a rootkit, and to build additional functionality on top, in the form of modular plug-ins.
To keep them under the antivirus radar, Nigerian actors techniques use "crypters" - software tools designed to encrypt, obfuscate, and modify malware.
GOZ, however, utilizes a P2P network of infected hosts to communicate and distribute data, and employs encryption to evade detection.
The criminals posed as employees of the business, moving thousands of dollars to overseas locations.
infected tens of millions of computers, harvested huge volumes of sensitive financial data
Trojans like ZeuS and SpyEye have the built-in ability to keep logs of every keystroke a victim types on his or her keyboard
others used it just as a piece of malware to log information that ZeuS collected from victims from either the keystroke logging, or the built-in POST data logging, which worked for both HTTP and HTTPS websites
In 2007 the first large scale attacks took place, that used the ZeuS bank attack configuration called “webinjects”... While ZeuS is a versatile malware kit... its key strength is in browser manipulation through the use of its dynamic configuration.
Information stealers seem to be the preferred type of malware to help in their fraudulent email attacks... The attacker can pilfer data about the targets and use it to create efficient messages for diverting transactions or asking money to be sent to fraudsters' account.
infected tens of millions of computers, harvested huge volumes of sensitive financial data
Trojans like ZeuS and SpyEye have the built-in ability to keep logs of every keystroke a victim types on his or her keyboard
others used it just as a piece of malware to log information that ZeuS collected from victims from either the keystroke logging, or the built-in POST data logging, which worked for both HTTP and HTTPS websites
Zeus distribution also relies on the registration of domain names for spamming, drive-by-download sites, and Zeus command-and-control domains.
The peer-to-peer layer merely functioned as a reliable and robust communication mechanism, and a way to hide the next layers of the infrastructure in order to become more resistant to takedown activity.
147 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The malware strain is linked to the Russian cyber criminal group Evil Corp, the group behind the Zeus and Dridex malware and associated with several large-scale ransomware and money laundering operations.
The malware is attributed to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with numerous ransomware and money-laundering operations.
SocGholish is linked to the Russian cyber‑criminal group Evil Corp. This group has previously been responsible for Zeus and Dridex malware and is also associated with several large‑scale ransomware and money‑laundering operations.
Banking trojan associated in the content with Evil Corp usage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.