EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/gameover-zeus
366/430

File EL-0065CriticalResolvedRansomware Attack / Banking Trojan / Botnet

GameOver Zeus

Also filed as Zeus Botnet · Zeus Malware

GameOver Zeus was one of the most notorious and profitable botnets in history, specializing in banking fraud. It operated by infecting victim machines to steal credentials and execute fraudulent transactions. The botnet was highly sophisticated, capable of bypassing multiple security measures and maintaining persistence on compromised systems.

  • #botnet
  • #banking-trojan
  • #malware
  • #zeus
  • #credential-theft
  • #financial-fraud
Notoriety8/10
Event
1 Jan 2011
Disclosed
1 Jan 2011
Target
Global Banking Sector
Actor
GameOver Zeus Operators
Scale
Millions of credentials and transaction records.
Status
Resolved

01Summary

GameOver Zeus was a sophisticated banking Trojan that dominated the cybercrime landscape in the early 2010s. Its primary function was to establish a persistent foothold on infected computers, allowing operators to steal banking credentials, session cookies, and other sensitive financial data. The malware utilized various techniques, including keylogging and man-in-the-browser attacks, to capture user input directly from web browsers. Once credentials were harvested, the botnet could automate the process of logging into online banking portals and initiating unauthorized fund transfers, making it a massive threat to the global financial system. Its operational longevity and adaptability made it a benchmark for subsequent, more advanced banking trojans.

02Background

The early 2010s saw a massive increase in online banking and e-commerce, creating a vast, lucrative attack surface. Criminal groups capitalized on this by developing highly effective malware designed specifically to exploit user trust and the inherent vulnerabilities of web browsers and operating systems. GameOver Zeus emerged as a prime example of this trend, professionalizing the process of financial theft on a global scale.

03Key revelations

  1. 01The ability to automate the login process across multiple international banking platforms.
  2. 02The use of sophisticated anti-analysis techniques to evade detection by security software.
  3. 03The sheer scale of the financial theft, impacting countless individuals and institutions globally.

04Technical analysis

The malware typically consisted of multiple components: a downloader/dropper, the Zeus core module, and specialized modules for different banking targets. It was designed to communicate with a Command and Control (C2) server, receiving instructions for credential harvesting and transaction execution. Key modules included keyloggers and specialized form grabbers that intercepted data before it was encrypted by the browser, ensuring the operators received plaintext credentials.

Attack vector
Phishing emails, malicious websites, and drive-by downloads from compromised legitimate sites.
Attack method
Credential harvesting and automated financial transaction execution.
Initial access
Exploitation of user trust via phishing or drive-by downloads.
Lateral movement
Internal network scanning and exploitation of weak credentials.
Persistence
Registry modifications, scheduled tasks, and rootkit techniques.
Exfiltration
Encrypted communication channels (C2) to exfiltrate credentials and transaction details.
Tool / malware
Zeus
Malware family
Zeus
Malware type
Banking Trojan / Botnet

Vulnerabilities exploited

  • Browser vulnerabilities (general)
  • Operating System vulnerabilities (general)

MITRE ATT&CK techniques

  • T1056.001
  • T1566.001
  • T1071.001

05Threat actor

The operators were highly professional, functioning like a sophisticated criminal enterprise. They maintained a complex infrastructure of C2 servers, utilized multiple layers of obfuscation, and adapted their malware code rapidly to evade detection, suggesting significant technical expertise and resources.

Aliases

  • Zeus Botnet Operators
  • Zeus Group

MITRE groups

  • T1056.001
  • T1566.001

Attribution sources

  • Security Industry Analysis

06Victims and impact

Additional victims

  • Individual Users

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Financial Records
  • PII
  • Session Cookies

Notable documents

  • Zeus Malware Sample Analysis Reports

08Financial damage

Estimated losses ran into the hundreds of millions of dollars globally over its operational period.

09Timeline

  1. 2010-01-01Initial development and deployment of the Zeus botnet framework.
  2. 2011-01-01Peak operational period and widespread global impact of the botnet.
  3. 2013-12-31Decline in operational effectiveness due to security countermeasures and law enforcement action.

10Reaction and fallout

Public reaction

The public reaction was one of heightened awareness regarding online banking security, leading to increased adoption of multi-factor authentication (MFA) and stronger password policies.

Political impact

It forced financial institutions and governments to accelerate the adoption of advanced fraud detection systems and real-time transaction monitoring, recognizing the systemic risk posed by botnets.

Geopolitical consequences

The incident highlighted the vulnerability of global financial infrastructure to non-state, criminal actors, prompting increased international cooperation in cybercrime law enforcement.

11Legal

While specific arrests related to the core Zeus operators are difficult to confirm, the incident contributed significantly to the development of international cybercrime treaties and increased law enforcement focus on financial cybercrime.

Civil lawsuits

  • Class-action lawsuits against financial institutions for inadequate security measures.

12Aftermath

Policy changes

  • Mandatory implementation of Multi-Factor Authentication (MFA) for online banking.

Regulatory changes

  • Stricter compliance requirements for financial institutions regarding cybersecurity incident response and fraud prevention.

Security improvements

  • Deployment of behavioral biometrics and advanced endpoint detection and response (EDR) solutions.
  • Increased focus on network segmentation to limit lateral movement.

13Significance and legacy

Significance

GameOver Zeus is historically significant as a foundational model for modern, highly profitable, and adaptable banking trojans. It demonstrated the commercial viability of large-scale, automated financial crime, setting a precedent for subsequent, more targeted and complex malware campaigns.

Legacy

Its legacy is the permanent shift in cybersecurity focus toward behavioral analysis and endpoint protection, moving beyond simple signature-based detection. It also accelerated the global push for stronger authentication methods to protect digital financial assets.

14Disclosure and media

Authentication
Malware analysis and forensic evidence

Media partners

  • The Guardian
  • Reuters
  • Security Research Firms

Publishing organisations

  • Mandiant
  • Kaspersky Lab
  • Symantec

15Related files

Went on to inspire

  • LockBit

16Field notes

  1. 01The botnet was highly modular, allowing operators to easily add support for new banking targets or exploit new vulnerabilities.
  2. 02The sheer volume of funds stolen required coordination across multiple international jurisdictions, making attribution extremely difficult.

17Resolution

The botnet's operational effectiveness declined over time due to increased security research, law enforcement takedowns, and the adoption of MFA by major banks.

18Sources

Official documents

  • Mandiant Threat Reports on Zeus

References

  1. [1]Mandiant
  2. [2]Kaspersky Lab
  3. [3]Symantec
Fact sheetEL-0065

Dates

Event
1 Jan 2011
Started
1 Jan 2010
Ended
31 Dec 2013
Discovered
1 Jan 2011
Disclosed
1 Jan 2011
Resolved
31 Dec 2013
Ongoing
No

Target

Organisation
Global Banking Sector
Type
Financial Institution
Sector
Banking
Country
Global

Actor

Name
GameOver Zeus Operators
Type
Criminal Gang
Motivation
Financial gain through automated theft of banking credentials and funds.
Status
Active
Arrested
No
Convicted
No

Data

Volume
Millions of credentials and transaction records.
Sensitivity
Top Secret
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.