Gozi

Malware

⚠️ Overview

Gozi (also known as Ursnif, Gozi-NIH, and ISFB) is a banking trojan first identified in 2005 by security researchers who discovered its source code on a Russian-language hacking forum. It is categorized as a polymorphic infostealer and backdoor, primarily designed to harvest online banking credentials, personal identifiable information (PII), and perform man-in-the-browser attacks via web injects. The malware is attributed to a Russian-speaking threat group, and its author was later identified as "Johnny" (real name unknown) who sold the code on the market.

🔧 Technical Capabilities

Gozi propagates via spear-phishing emails containing malicious attachments (e.g., Word documents with macro scripts) or exploit kits that leverage vulnerabilities such as CVE-2014-0322 (Internet Explorer zero-day). Its attack chain involves a staged payload: a first-stage downloader fetches the main DLL payload from a remote server using HTTP or HTTPS communication to a dynamic C2 infrastructure. The malware employs domain generation algorithms (DGAs) and fast-flux hosting to evade takedowns. For persistence, it installs itself as a Windows service or writes registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include code obfuscation, anti-debugging checks, and encryption of network traffic with RC4 or AES. Once resident, Gozi hooks browser APIs (e.g., Wininet.dll) to intercept HTTP POST data and inject malicious overlays into financial websites.

📜 History & Notable Incidents

Gozi first appeared in 2005 and gained notoriety after its source code was leaked in 2015, spawning numerous variants used by ransomware groups and other criminal enterprises. In 2012, Romanian national Mihai Ionuț Păunescu was arrested for distributing Gozi variants and was later extradited to the United States, pleading guilty in 2017 for his role in a large-scale banking fraud scheme that infected over one million computers globally. A notable campaign in 2013 targeted U.S. and UK financial institutions, resulting in losses estimated at tens of millions of dollars. The malware exploited CVE-2014-0322 (an Internet Explorer zero-day) in drive-by download attacks and was linked to the Gozi Group, which also operated the Kelihos botnet at various times.

🔍 Detection Indicators

Known file hashes include SHA256: 0a5c0f3f8c9b8e4a3d2c1b6e9a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (example placeholder; real hashes vary per variant). Behavioral indicators include a service named "Gozi Service" or "Ursnif Updater" writing to %AppData%LocalTemp[8-char random].dll. Network IOCs include HTTP POST requests to domains with patterns like "*.topmails.info" and User-Agent strings such as "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0)". Registry artifacts include a mutex named "GlobalGoziMutex" and a value "Gozi_Update" under the Run key.

☠️ Risk & Impact

The primary impact of Gozi is credential theft and financial fraud, with the malware able to exfiltrate banking credentials, credit card numbers, and session tokens via web injects. Large-scale campaigns have resulted in multi-million dollar losses for banks and corporate accounts, particularly affecting personal banking and corporate treasury sectors. The malware also provides a backdoor for subsequent ransomware deployment, as seen in some post-2015 variants.

🛡️ Mitigation

Recommended defenses include implementing robust email filtering to block phishing attachments, keeping browsers and plugins patched (especially against CVE-2014-0322), and using endpoint detection and response (EDR) solutions that flag behavior such as browser hooking and unauthorized API calls. Network-level blocking of known C2 domains (via threat feeds from sources like Proofpoint or CrowdStrike) and application whitelisting can further reduce risk. Regular user awareness training on phishing tactics is also essential.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.