GameOver Zeus, also known as GoZ, was a peer-to-peer evolution of the ZeuS banking malware lineage operated by actors associated with the Business Club cybercriminal ecosystem and linked to Maksim Bogachev. It functioned as a modular banking trojan and botnet used to steal online banking credentials and support fraudulent financial activity, while also providing resilient command-and-control through a decentralized architecture. GameOver Zeus is widely regarded as a predecessor and influence on later malware families including Dridex, which incorporated characteristics associated with GoZ. By 2011, the GameOver Zeus botnet was also used to deploy CryptoLocker ransomware, demonstrating its role as a delivery platform for additional criminal payloads. Its infrastructure was disrupted in 2014 through coordinated law-enforcement action, after which successor activity and malware development within the same criminal milieu contributed to the emergence of families such as Dridex and Geodo/Emotet. GameOver Zeus primarily targeted Windows systems and was a major component of financially motivated cybercrime operations focused on banking theft and large-scale botnet activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dridex, apparu en juin 2014, est la cinquième variante du code malveillant Bugat actif de 2010 à 2013, agrémenté de particularités propres à GameOverZeuS (GoZ), actif jusqu’en 2014.
In September 2011 GameOverZeus (botnet GoZ) was now able to deploy Cryptolocker Ransomware.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet variant of Zeus mentioned in historical context as capable of deploying CryptoLocker.
ZeuS-derived P2P banking botnet whose techniques and lineage influenced Dridex; it also propagated CryptoLocker and used Cutwail and Pony Loader in its infection chains.
Historical Zeus-derived malware operated by precursor actors connected to Emotet's lineage.
Banking trojan/botnet mentioned only as historical background to TrickBot lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.