The Gameover Zeus malware has returned from the dead, stronger and deadlier than before. U.S authorities had stated as recently as six weeks ago that they had broken up a major hacker network by taking control over the internet infrastructure being used by the GameOver Zeus (GOZ) malware and CryptoLocker ransomware threats. And even as the Department of Justice claimed that they had made progress in weeding out the malware infection, Zeus struck again.
History of Zeus Malware
Gameover Zeus first appeared in September 2011. FBI had held Gameover Zeus botnet responsible for the theft of more than $100 mn, since then.
One million computers were hijacked around the world to send spam, launch malware attacks and thereby steal bank credentials. The money was stolen by using the stolen bank data which was then used to divert the money from the victim’s account to themselves.
In a bid to catch the alleged mastermind behind the GameOver Zeus and infamous CryptoLocker ransomware gang, FBI had published a “Wanted Poster” of Evgeniy Mikhailovich Bogachev. They were hoping that someone might spot him in the public and they could then capture him.
Is Gameover Zeus really back?
Analysts have confirmed with FBI that the original GameOver Zeus is still “locked down.” The new Trojan is an advanced and more resilient form of the GameOver Zeus binary and was spread as messages in an attachment from the NatWest bank, the Essentra packing company, and M&T Bank. Once the user opens the attachment, the malware starts making contact with certain websites, which in turn can provide instructions to the malware.
A security firm stated that the new Trojan can prove to be harder to deal with as it is using “an evasive technique that allows the botnet to hide its distributive phishing sites behind a constantly shuffling list of infected, proxy computers.” It is being speculated to be designed to steal sensitive information like log-in credentials and financial information.
While it’s too early to say whether this new Trojan will be as effective as its predecessor, the fact that it surfaced within a month of the FBI’s takedown operation, gives clear indications about the intent of the perpetrators. They are in no mood to give up this botnet which made their wallets heavier by a $100 mn.
Founder & Chief Marketing Officer, Indusface
Venky has played multiple roles within Indusface for the past 6 years. He was instrumental in building the product/service and technology team from scratch and grew it from ideation to getting initial customers with a proven/validated business model poised for scale. He has proven experience (10+ years) in the security industry and has held various mgmt/leadership roles in Product Development, Professional Services, and Sales during his time at Entrust Data card.