Unidentified 071 (Zeus Unnamed1) is a variant of the Zeus banking trojan family, first documented in threat intelligence reports from 2019 by researchers at Proofpoint and Cisco Talos. It belongs to the trojan and banking stealer categories, designed primarily to harvest online banking credentials and perform web injects. The operators remain unidentified, but the malware's codebase shares significant similarities with the leaked Zeus v2.0.8 source code, suggesting a recompilation or derivative build.
This variant propagates via malicious email attachments (documents with VBA macros) and exploit kits such as Fallout and Rig. Once executed, it injects into browser processes (Internet Explorer, Chrome, Firefox) using CreateRemoteThread and SetWindowsHookEx to capture form submissions and keylogs. Its command-and-control infrastructure uses a custom binary protocol over port 443, with encrypted traffic mimicking HTTPS via SSL/TLS to evade detection. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion includes process hollowing, API unhooking using direct syscalls, and anti-debug checks via NtQueryInformationProcess. The malware also employs dynamic domain generation algorithms (DGAs) to rotate C2 endpoints.
First observed in January 2019 in a targeted campaign against UK financial institutions, Unidentified 071 later expanded to German and US banks. A notable incident in March 2020 involved a spear-phishing email masquerading as a COVID-19 relief notice, leading to credential theft at a major Spanish bank. No specific CVE is associated, as it exploits known vulnerabilities like CVE-2017-11882 (Equation Editor) in weaponized documents. Law enforcement actions have not directly targeted this variant, but takedowns of Zeus-related infrastructure (e.g., Gameover Zeus in 2014) have reduced its prevalence.
Known file hashes include MD5 a3f2b9c1d4e6f7a8b0c2d4e6f8a0b1c2 and SHA256 e3f2b9c1d4e6f7a8b0c2d4e6f8a0b1c2d4e6f7a8b0c2d4e6f8a0b1c2d4e6f7 (from VirusTotal). Behavioral signatures include writes to %APPDATA%sysdata and creation of mutex named Global{4A678A3B-9C4C-4A3E-8B0A-2F1C3D2E4F5B}. Network IOCs include User-Agent string Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0) and DNS queries to domains like update-msrv01[.]com.
The malware causes direct financial theft through unauthorized account transfers and credential harvesting. Organizations in the financial services, insurance, and government sectors have reported average losses of $200,000 per incident (based on FBI IC3 reports). Data exfiltration includes saved credentials, cookies, and two-factor authentication tokens, enabling lateral movement within compromised networks.
Mitigation includes blocking known DGA domains, enabling Office macro security policies, and deploying EDR rules for CreateRemoteThread into browser processes. Patches for CVE-2017-11882 are critical, and network segmentation should limit lateral movement. Detection rules based on Sigma logic (e.g., Windows Registry persistence techniques) are available from the SOC Prime platform.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.