Vawtrak, also known as Neverquest and referred to in one source as “Gozi 2 Prinimalka,” is an e-banking Trojan/banking Trojan associated with credential theft and online banking fraud. The content explicitly describes banking trojans such as Vawtrak as using man-in-the-browser techniques to steal credentials from targeted victims. It is also referenced as part of the broader Gozi lineage, with one source stating that the Kuzmin Gang evolved Gozi v1 into Gozi v2, which later became “Gozi 2 Prinimalka,” also called Vawtrak.
The malware appears in multiple delivery and hosting contexts in the provided content. Hancitor was observed in its early years delivering Vawtrak. H1N1 is described as a loader variant known to deliver Vawtrak executables to infected machines. Bedep build 1926 was observed delivering Vawtrak campaigns 13 and 60 in November 2015 during Angler exploit kit-related malvertising activity. The content also states that Vawtrak payloads were likely delivered in exploit-kit activity involving Neutrino, and that URLZone had been observed loading Vawtrak and other banking trojans. Avalanche infrastructure hosted Vawtrak/Neverquest as part of a large criminal fast-flux ecosystem used for phishing, malware distribution, and botnet communications.
The provided content ties Vawtrak to financially motivated cybercrime ecosystems rather than a single exclusive operator. It is associated with banking-trojan activity, exploit-kit delivery, spam/downloader delivery chains, and criminal hosting infrastructure. Mentioned infrastructure and indicators include Vawtrak command-and-control servers ninthclub[.]com (81.177.22.179) and atlasbeta[.]com (176.9.188.147), identified in the Bedep/Angler-related reporting. The content also notes that Avalanche-linked malware, including Vawtrak, targeted Microsoft Windows systems and activity affecting major financial institutions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Neutrino firing his bundle of Sploit : 2015-02-06 Note: in this pass the Vawtrak payload is most probably CVE-2014-6332 load | note that CVE-2014-6332 is in RIG as well ... Note: in this pass the Vawtrak payload is most probably CVE-2014-6332 load
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude
7 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2015-0311 has been first seen exploited by Angler EK ... soon after used in "standalone" mode in huge malvert campaign ... CVE-2015-0311 has been integrated today in RIG ... Fiesta successfully exploit Windows XP IE8 Flash 16.0.0.257 using CVE-2015-0311 ... Nuclear Pack successfully exploit ... using CVE-2015-0311 ... Sweet Orange firing exploit for CVE-2015-0311 ... Neutrino firing his bundle of Sploit ... Magnitude - CVE-2015-0311 exploited successfully
Active since 2009, the Avalanche botnet has been used for money muling schemes, distributing a wide variety of malware, and as a fast-flux communication infrastructure for other botnets.
The Hancitor malware, first observed in 2015, is a downloader known to deliver several other malware. In its first years, Hancitor was observed delivering information stealers such as Pony or Vawtrak, and in recent years, Ficker stealer and NetSupport RAT. In 2021, Hancitor was observed delivering the Cobalt-Strike attack framework...
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A later Gozi evolution developed by the Kuzmin Gang from Gozi v1 into Gozi v2/Prinimalka, also known as Vawtrak.
Vawtrak is mentioned as an information stealer delivered by Hancitor in earlier campaigns.
Banking trojan referenced as a payload previously loaded by URLZone in campaigns targeting Japan.
E-banking trojan associated with botnet controllers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.