GameOver Zeus, also known as Peer-to-Peer Zeus, was a private-build Zeus-family banking trojan operating from approximately 2011 until its multinational disruption in 2014. It targeted Microsoft Windows systems and used a decentralized peer-to-peer botnet architecture, proxy nodes, and domain-generation functionality to sustain command-and-control resilience. The malware conducted man-in-the-browser attacks, including web injection and manipulation of legitimate banking pages, to capture banking and other online credentials and additional financial information. Operators used stolen credentials to initiate or redirect fraudulent wire transfers to accounts under criminal control, causing losses estimated at more than $100 million. GameOver Zeus could deploy additional payloads and was a principal distribution mechanism for CryptoLocker ransomware. The botnet was also used for distributed denial-of-service attacks, including attacks against victims and financial institutions following theft. U.S. authorities alleged that Evgeniy Mikhailovich Bogachev administered the botnet as part of a Russian- and Ukrainian-linked criminal enterprise. A coordinated law-enforcement and private-sector operation disrupted the botnet through peer-list manipulation, proxy-layer controls, domain-generation takeover, sinkholing, and court-authorized infrastructure actions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gameover Zeus – Bad Guys and Backends ... Gameover Zeus September 2011 – June 2014 Private builds, introduced P2P protocol
GameOver ZeuS, GOZ, peer-to-peer ZeuS, P2P-ZeuS and ZeuS3 are analogous to each other and refer to a ZeuS based malware family, which was active in the wild from September 2011 till May 2014.
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
"...operated the Zeus and Gameover Zeus botnets until international law enforcement action in May 2014."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
the samples were downloaded from a compromised website located in the United States... Gameover Zeus has also been distributed by the Blackhole and Magnitude exploit kits.
Infection Method Blackhole Exploit Kit • Specific configuration for Gameover Zeus
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
During our research, we found a large amount of search queries which were executed on the victim systems. The search queries consisted of a number of keywords... focused on locating “government classified” material
The principal purpose of GOZ is to capture banking credentials from infected computers. One means by which GOZ accomplishes this is through ... attacks, in which GOZ intercepts sensitive information victims transmit from their computers.
even in its early days, the malware could receive dynamic configuration files, use web injections to steal money
The principal purpose of the botnet is to capture banking credentials from infected computers.
Espionage ... Targeting government and intelligence agencies ... foreign intelligence ... counter intelligence ... top secret
The token-grabber attack in peer-to-peer ZeuS... The victim would see a normal, or almost normal, login page of their bank... During the victim being on hold, the browser would continuously poll the backend to check if new questions were available to ask the victim.
Dridex has been able to escape justice for so long by hiding its main command-and-control (C&C) servers behind proxying layers.
It uses a tiered, decentralized system of intermediary proxies and strong encryption to hide the location of servers that the botnet masters use to control the crime machine.
By early 2015, Dridex implemented a kind of P2P network... some peers (supernodes) had access to the C&C and forwarded requests from other network nodes to it.
The Necurs botnet has historically been used to deliver a torrent of other high profile cyber threats to the world, including the GameOver Zeus and Dridex banking trojans, Locky ransomware and, more recently, the banking trojan turned all purpose cybercrime-as-a-service, Trickbot.
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a prior botnet disruption that used peer-list manipulation.
Mentioned only as a historical example of a botnet disruption using peer-list manipulation.
Referenced as a peer-to-peer banking trojan/botnet used for banking fraud, malware distribution, and intelligence collection.
Malware used as a primary distribution mechanism for CryptoLocker; it was downloaded by Upatre and then installed additional malware families including CryptoLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.