JabberZeuS is a customized ZeuS-derived banking trojan associated with the Business Club cybercriminal ecosystem and the broader lineage that later included GameOverZeuS. It was developed as a bespoke variant of ZeuS for a criminal gang that maintained direct contact with the ZeuS author. A defining feature of JabberZeuS was its use of the XMPP/Jabber protocol to send real-time notifications to operators when an infected victim accessed a bank account meeting attacker-defined criteria, enabling rapid cash-out operations through coordinated money-mule networks.
Its primary purpose was theft of online banking credentials and facilitation of fraudulent transfers, particularly against businesses in the United States and Europe. Operationally, JabberZeuS formed part of an organized fraud workflow in which stolen credentials were relayed to operators and accomplices managed mule recruitment and fund extraction. The malware is historically significant as an intermediate stage in the evolution from ZeuS to GameOverZeuS, and reporting on the Business Club and Evil Corp lineages places JabberZeuS within the criminal development arc that influenced later large-scale banking malware operations.
High-confidence reporting supports JabberZeuS as a Windows-focused banking trojan used for credential theft and post-compromise fraud enablement. Specific initial infection vectors are not established here with sufficient confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cette version, agrémentée de l’utilisation du protocole XMPP, sera baptisée JabberZeuS.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
infected tens of millions of computers, harvested huge volumes of sensitive financial data
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ZeuS variant built for a cybercrime gang. A notable feature was sending Jabber instant messages when a victim logged into a bank account with a high balance, enabling rapid theft operations.
Enhanced ZeuS variant used by the Business Club/Evil Corp precursor, notable for XMPP-based notifications about compromised banking sessions; included as part of the lineage leading to Dridex operators.
Historical Zeus-family malware mentioned as part of the lineage of actors tied to Emotet's origins.
Banking trojan mentioned only as historical background to TrickBot lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.