Zeus Sphinx (also tracked as Zbot-Sphinx or Sphinx) is a sophisticated banking trojan first identified in early 2015 by researchers at IBM X-Force, originating from the leak of the Zeus 2.0 source code in 2011 and subsequently maintained by an Eastern European cybercriminal group known as TA544 or the "Sphinx Team." This malware belongs to the credential-stealing and financial malware category, specifically designed to harvest online banking credentials, perform web injects, and exfiltrate sensitive data via man-in-the-browser attacks.
Zeus Sphinx leverages dynamic web injects delivered through a modular plugin system, allowing real-time modification of banking website content to steal login credentials, two-factor authentication tokens, and credit card details. Its propagation relies primarily on malicious email attachments—typically macro-laden Office documents or JavaScript downloads—and drive-by downloads from compromised websites. The malware establishes command-and-control (C2) communication over encrypted HTTP or HTTPS channels using domain generation algorithms (DGAs) and fast-flux DNS to evade takedown. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include process hollowing to inject into legitimate processes like svchost.exe, anti-debugging checks, and the use of encrypted configuration files to hide C2 endpoints.
First observed in 2015 targeting UK and US financial institutions, Zeus Sphinx was notably implicated in a 2017 campaign against Australian banks (e.g., Westpac and Commonwealth Bank) that compromised over 1,000 accounts. No specific CVEs are directly associated with Sphinx itself, but it frequently exploits Microsoft Office vulnerabilities (e.g., CVE-2017-0199 for HTA execution) and leverages phishing lures using tax-themed or invoice emails. In 2018, law enforcement conducted a coordinated sinkholing operation that disrupted several Sphinx C2 domains, though the group remains active as of 2024.
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from early samples; verifiable via VirusTotal). Behavioral indicators include creation of mutex names like _AVAST_ and SphinxMutex for anti-sandbox checks. Network IOCs include User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36 and outbound connections to domains ending in .ru or .su. Persistence artifacts include registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named WindowsUpdate or AdobeFlashPlayer.
Zeus Sphinx primarily causes financial theft through automated account takeovers and fraudulent transactions, with losses per incident averaging $5,000–$50,000 per compromised account. The malware also exfiltrates personal identifiable information (PII) and credit card data, leading to identity theft and secondary fraud. Affected sectors include retail banking, online payment services, and cryptocurrency exchanges, with reported incidents in Australia, the United States, and Europe as documented by IBM X-Force's 2019 report on "Banking Trojans in the Wild."
Defensive measures include deploying multifactor authentication (MFA) not reliant on SMS, applying Microsoft Office updates to block weaponized documents (e.g., CVE-2017-0199 patches), and implementing endpoint detection and response (EDR) rules for process hollowing and suspicious registry modifications. Network-level defenses should block known DGA domains using threat intelligence feeds from sources like the Abuse.ch Zeus Tracker and enforce application whitelisting to prevent unauthorized process injection.
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.