Shiz is a long-running banking Trojan family associated with financially motivated cybercrime and regarded as one of the older banking malware codebases still seen in the wild. It has been linked to the evolution of later banking malware, most notably Shifu, which is widely assessed as being derived from or representing a later evolution of the Shiz/iBank lineage with additional techniques influenced by Zeus.
Shiz has been observed in the Windows crimeware ecosystem as a payload distributed by other malware delivery operations, including Bredolab, and as a service or botnet resource used by criminal groups such as Carbanak. Its role in those ecosystems indicates use as a modular banking-focused payload rather than a standalone intrusion platform. Historical reporting also places Shiz among notable mobile and banking botnets active in the mid-2010s, though the strongest corroborated evidence in this context ties it to Windows-based banking Trojan activity.
The family is associated with credential theft from online banking users and with the broader banking Trojan tradecraft of intercepting or abusing financial sessions. Its code lineage influenced later malware that used multi-stage loading, process injection into legitimate Windows processes, persistence through user startup mechanisms, anti-analysis checks, API obfuscation, traffic interception, web-injection support, and command-and-control concealment. However, those latter implementation details are directly established for Shifu as a descendant or evolution of Shiz rather than for all Shiz variants themselves.
Shiz is notable in threat history both as an operational malware family used by cybercriminal partners and as a foundational codebase that informed subsequent banking Trojans. It sits within the broader ecosystem of financially motivated malware used against banking customers and financial institutions, especially in campaigns targeting online banking credentials on Microsoft Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
D’après Group-IB, Carbanak aurait souscrit à des services de botnets (tels que GoZ, Shiz et Ranbyus).
2 distinct techniques documented for this family, organized by ATT&CK tactic.
94 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Shiz is a malware family discussed in the weekly malware review. The content does not provide further details on its functionality or purpose.
Another malicious program whose modules were found inside a TDL-3 encrypted disk; its creators reportedly operated a search-engine redirect affiliate program using TDL-3.
A secondary payload distributed by Bredolab; its seller parameter is cited as evidence of partner-based malware distribution.
Mentioned as prior Android banking malware for historical comparison.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.