SpyEye is a Windows banking trojan/crimeware toolkit active primarily from 2009 to 2011 and widely used to steal online banking credentials, credit card data, and other sensitive information. It targets major browsers including Internet Explorer, Firefox, Chrome, Opera, and Safari on Microsoft Windows. Reported capabilities include keystroke logging, form grabbing, web injects/HTML injection, and man-in-the-browser style credential theft. SpyEye can modify banking pages shown to victims, prompt for additional credentials or card data, and hide fraudulent transactions by displaying falsified balances or transaction history. Some versions added form-grabbing support for Chrome and Opera, and the malware has been described as using memory-injection-based keylogging techniques. It communicates with command-and-control servers and was sold and customized for customers on underground forums, with reported pricing from roughly $500 to several thousand dollars depending on version or customization.
SpyEye was marketed as a rival and successor to ZeuS, including under the label "ZeuS Killer," because it could search for and remove ZeuS from infected systems before installing itself. Multiple reports state that after ZeuS development slowed, its source code or rights were transferred to the SpyEye developer, and components of ZeuS were later incorporated into SpyEye. The malware was used in large-scale financial theft, including botnets linked to more than $100 million in losses from small and mid-sized businesses in the United States and abroad. It was also used in broader fraud operations such as Operation High Roller, where Zeus or SpyEye were used for reconnaissance and automated banking fraud against commercial banking customers, including organizations in manufacturing, state and local government, and import/export sectors.
High-confidence attribution in the provided content identifies Aleksandr Andreevich Panin, aka Gribodemon/Harderman, as the primary developer and distributor of SpyEye, with Hamza Bendelladj, aka Bx1, identified as an accomplice who helped refine, market, and operate SpyEye-related botnets. Panin pleaded guilty in the United States, and Bendelladj also pleaded guilty and was sentenced. The content states SpyEye infected more than 1.4 million computers in the United States and other countries and compromised at least 10,000 bank accounts in one cited year. Reported infrastructure included command-and-control servers, including one seized by the FBI in Georgia that controlled more than 200 infected computers. Microsoft also conducted a 2012 takedown of dozens of botnets powered by ZeuS and SpyEye, seizing servers and domains used in their infrastructure.
Infection vectors mentioned in the content include phishing emails with malware-laden attachments, spam distribution by botnets such as Cutwail, and compromised websites used in malware operations. Known operational indicators from the content include use of web injects, command-and-control servers, and botnet infrastructure; one cited sample/reference is "SpyEye 324 eBanking Trojan."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
In November 2010, Panin allegedly received the source code and rights to sell Zeus from Evginy Bogachev, a/k/a Slavik, and incorporated many components of Zeus into SpyEye.
Bendelladj also admitting to running his own SpyEye botnet of hacked Windows computers, a crime machine that he used to harvest and steal 200,000 credit card numbers.
Bendelladj also admitting to running his own SpyEye botnet of hacked Windows computers, a crime machine that he used to harvest and steal 200,000 credit card numbers.
Trojans like ZeuS and SpyEye have the built-in ability to keep logs of every keystroke a victim types on his or her keyboard
Screenshots from the package show that the latest rendition comes with the option for new “form grabbing” capabilities targeting Chrome and Opera users.
Microsoft received court approval to seize several servers in Scranton, Penn. and Lombard, Ill. used to control dozens of ZeuS and SpyEye botnets. The company also was granted permission to take control of 800 domains that were used by the crime machines.
The malware communicated with command-and-control servers; one which was controlled by Bendelladj and located in Georgia.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware family whose author was identified as a Darkode forum user.
Banking trojan described as part of the malware lineage enabled by the leaked ZeuS source code.
Credential-stealing banking malware that uses keystroke logging and form grabbing, performs web/HTML injection to add or alter fields on banking pages, and can hide fraudulent transactions by displaying a false balance to the victim while enabling theft from online bank accounts.
SpyEye is a banking malware and botnet toolkit used to infect Windows computers, steal financial data including credit card information, and facilitate bank and wire fraud. It was marketed as a more powerful, lower-cost alternative to Zeus and was designed to remove Zeus from infected hosts before installing itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.