GozNym is a banking trojan that combines elements of the Gozi/ISFB code base with the Nymaim delivery ecosystem. It emerged in 2016 and was used in large-scale financially motivated campaigns against businesses and financial institutions, primarily in the United States and Europe. The malware was associated with a cybercrime-as-a-service operation in which different actors handled malware development, phishing-based distribution, crypting, bulletproof hosting, account takeover, and cash-out functions.
Its core purpose was theft of online banking credentials and subsequent fraudulent access to victim bank accounts. Operators used the stolen credentials to initiate unauthorized transfers and launder proceeds through networks of beneficiary accounts. GozNym infections were linked to tens of thousands of compromised systems and roughly $100 million in attempted fraud. The malware was also tied to the Avalanche criminal infrastructure, which provided resilient hosting and command-and-control support for numerous malware campaigns before its 2016 takedown.
GozNym is widely described as a hybrid of Gozi and Nymaim. Nymaim contributed dropper and delivery functionality, while Gozi-derived capabilities supported banking credential theft and fraud operations. Campaigns distributing GozNym relied on phishing spam designed to appear legitimate and induce victims to open malicious links or attachments. The family also benefited from crypting services intended to reduce antivirus detection.
Law enforcement actions in the United States and Europe significantly disrupted the ecosystem. International investigations led to indictments, arrests, extraditions, convictions, sinkholing activity, and prosecutions across multiple countries. GozNym remains notable as an example of modular banking malware built from leaked criminal code bases and operated through specialized underground service providers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
use the captured login credentials to fraudulently gain unauthorized access to victims’ online bank accounts
The spamming operations involved the mass distribution of GozNym malware through “phishing” emails. The phishing emails were designed to appear legitimate to entice the victim recipients into opening the emails and clicking on a malicious link or attachment, which facilitated the downloading of GozNym onto the victims’ computers.
Alexander Konovolov, aka “NoNe,” and “none_1,” age 35, of Tbilisi, Georgia, was the primary organizer and leader of the GozNym network who controlled more than 41,000 victim computers infected with GozNym malware.
Nymaim on its own is a dropper. It acts solely as a gateway—a delivery system for other strands of malware. GozNym uses Nymaim’s advanced stealth capabilities to unload the previously mentioned Gozi malware.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PC banking trojan listed among malware actively used to attack companies.
Malware used in a criminal conspiracy to steal funds, in conjunction with Avalanche infrastructure.
Mentioned as a project that spawned from the 2015 ISFB leak.
A banking malware family mentioned as one of the cybercriminal groups that used QQAAZZ’s services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.