ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Home > List all groups > List all tools > List all groups using tool GameOver Zeus

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: GameOver Zeus

NamesGameOver Zeus
Peer-to-Peer Zeus
P2P Zeus
TypeBanking trojan, Info stealer, Credential stealer, Downloader, Botnet
Description(US-CERT) GOZ, which is often propagated through spam and phishing messages, is primarily used by cybercriminals to harvest banking information, such as login credentials, from a victim’s computer. Infected systems can also be used to engage in other malicious activities, such as sending spam or participating in distributed denial-of-service (DDoS) attacks.

Prior variants of the Zeus malware utilized a centralized command and control (C2) botnet infrastructure to execute commands. Centralized C2 servers are routinely tracked and blocked by the security community. GOZ, however, utilizes a P2P network of infected hosts to communicate and distribute data, and employs encryption to evade detection. These peers act as a massive proxy network that is used to propagate binary updates, distribute configuration files, and to send stolen data. Without a single point of failure, the resiliency of GOZ’s P2P infrastructure makes takedown efforts more difficult.
AlienVault OTX<>

Last change to this tool card: 24 April 2021

Download this tool card in JSON format

Previous: Gamaredon
Next: GandCrab

All groups using tool GameOver Zeus


APT groups

 TA505, Graceful Spider, Gold EvergreenRussia2006-Nov 2022X

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]