VM-ZeuS, also referred to as KINS in the provided content, is a malware family associated with the Avalanche criminal infrastructure. The content places it among malware families hosted on Avalanche, a large global fast-flux and double-fast-flux criminal hosting and botnet communication platform active since 2009 and disrupted by international law enforcement in 2016. Avalanche supported phishing campaigns, malware distribution, and money mule schemes, and affected Microsoft Windows systems. Malware hosted on this infrastructure was used against more than 40 major financial institutions and was capable, at an ecosystem level, of stealing credentials and other sensitive information including banking and credit card data, enabling unauthorized remote access, distributing additional malware, participating in distributed denial-of-service activity, and in some cases encrypting files for ransom. High-confidence malware-specific detail in the content is limited to the identification of VM-ZeuS as a hosted malware family on Avalanche and its alias KINS; no distinct infection vector, technical behavior, or indicators of compromise specific to VM-ZeuS/KINS are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Active since 2009, the Avalanche botnet has been used for money muling schemes, distributing a wide variety of malware, and as a fast-flux communication infrastructure for other botnets.
Active since 2009, the Avalanche botnet has been used for money muling schemes, distributing a wide variety of malware, and as a fast-flux communication infrastructure for other botnets.
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan listed among malware families hosted by Avalanche.
Zeus-related banking trojan listed among malware hosted by Avalanche.
Banking trojan variant hosted on Avalanche infrastructure and associated with credential theft and financial fraud.
Zeus-derived banking trojan variant whose C2/infrastructure was hosted on Avalanche.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.