The ZeuS banking Trojan emerged as a dominant crimeware kit used to steal online banking credentials, browser-submitted form data, cookies, certificates, and files, while also enabling attackers to modify web pages, redirect victims, and execute arbitrary programs on infected systems. Reports describe ZeuS as a commercially sold toolkit priced around $3,000–$4,000, with add-on modules for capabilities such as backconnect access, VNC control, Firefox form grabbing, and Windows Vista/7 support. Its architecture evolved across the 1.2.x, 1.3.x, and 1.4.x branches to add stronger encryption, web injects, API hooking, anti-analysis protections, random file names and mutexes, and RC4-encrypted communications with command-and-control servers, while commonly injecting into processes such as winlogon.exe or explorer.exe.
The malware’s ecosystem also expanded into both competition and mobile fraud. SpyEye was marketed as a cheaper rival and introduced "ZeusKiller" to remove or hijack existing ZeuS infections, while ZeuS itself adopted hardware-based licensing and continued adding premium criminal features. A related mobile component, ZeuS-in-the-Mobile (ZitMo), was used to intercept SMS-based transaction authentication numbers by tricking banking victims into installing fake mobile security software, allowing attackers to complete fraudulent transfers after harvesting credentials on the PC. More recent reporting also tied the KINS Zeus variant to a malvertising campaign targeting European transit users, where victims were redirected to malware disguised as a PDF, protections such as Windows Defender were weakened via registry changes, and the payload used characteristic POST traffic and inbound connectivity to maintain control.

Pull IOCs and campaign context straight into your stack.
22 events from the most recent confirmed update back to the earliest known activity.
The Zscaler analysis referenced KINS command-and-control callback activity during January and February 2015, tying the Zeus-derived crimekit to active bot communications in that period.
By October 2011, ZitMo variants had been detected for Symbian, Windows Mobile, BlackBerry, and Android, showing the malware family had expanded beyond its initial platforms.
By July 2011, identified ZitMo command-and-control phone numbers were UK numbers, providing additional infrastructure insight into the mobile banking malware campaigns.
In early July 2011, researchers detected an Android ZitMo variant that differed from earlier SMS-commanded versions by forwarding all incoming SMS messages to a remote server via HTTP.
On 2011-06-18, an Android ZitMo sample was uploaded to Android Market, where it was downloaded fewer than 50 times before removal.
On 2011-02-21, a Polish blogger reported a second known ZitMo campaign targeting customers of ING and mBank, with Symbian and Windows Mobile variants using the same command-and-control number.
ZeuS-in-the-Mobile was first detected on 2010-09-25, and S21sec publicly reported the first known threat in September 2010 involving malware designed to intercept mTAN SMS codes in support of PC-based ZeuS banking fraud.
On 2010-01-11, version 1.3.2.0 was dated with a fix for a serious deadlock bug affecting builds with nspr4.dll support.
On 2009-11-22, ZeuS 1.3.0.0 was dated with major changes including WinAPI interception by splicing, full Windows Vista and Windows 7 functionality, rewritten FTP and POP3 sniffing, IPv6 support, and revised certificate theft behavior.
On 2009-10-17, version 1.2.10.0 was dated with full integration of a Jabber notifier into the control panel.
On 2009-10-10, ZeuS 1.2.9.0 was dated with password grabbing for multiple FTP clients including FileZilla, WinSCP, WS_FTP, SmartFTP, and others.
On 2009-10-05, version 1.2.8.0 was dated with performance improvements to its SOCKS server and other built-in protocols by enabling TCP_NODELAY.
On 2009-06-22, ZeuS 1.2.7.0 was dated with additions including process owner usernames in reports and the ability to disable the phishing filter in Internet Explorer 7 and 8.
On 2009-06-04, version 1.2.6.0 was dated with added interception of nspr4.dll.
On 2009-05-27, ZeuS 1.2.5.0 was dated with a control-panel fix for a gate.php vulnerability that allowed writing files into parent directories.
On 2009-03-28, version 1.2.3.0 was dated with a protocol change for distributing commands to bots.
On 2009-03-11, ZeuS 1.2.2.0 was dated with a fix for a long-standing HTTP injection bug tied to asynchronous wininet.dll thread synchronization, and it modified local cache files to improve injection reliability.
On 2008-12-30, version 1.2.1.0 was dated with fixes for report-sending problems, including a roughly 550-character report size limit and POST timeout issues on slow connections.
On 2008-12-20, the ZeuS author dated version 1.2.0.0, which completely updated the bot-to-server protocol, encrypted local data, requests, and configuration with RC4, and introduced a new PE cryptor and revised build process.
In reporting published on 2010-04-01, SpyEye was described as a newer competing crimeware kit that could hijack or remove existing ZeuS infections via its ZeusKiller feature and offered browser injection capabilities for Firefox and Internet Explorer.
By early April 2010, Krebs reported that the ZeuS author was releasing version 1.4 with a higher base price, while SecureWorks had also described an upcoming 1.4 beta adding Firefox web injects and polymorphic encryption.
On 2010-03-10, SecureWorks CTU published a threat analysis describing ZeuS as a leading financial-fraud crimeware kit, detailing its capabilities, pricing, modules, RC4-encrypted C2 traffic, and hardware-based licensing controls.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcesans.org
Open sourcesecurelist.com
Open sourcecontagiodump.blogspot.com
Open sourcekrebsonsecurity.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.