SYMBOLCOMMON_NAMEaka. SYNONYMS

GozNym  (Back to overview)


IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its source code with part of the Gozi ISFB source code, creating a combination that is being actively used in attacks against more than 24 U.S. and Canadian banks, stealing millions of dollars so far. X-Force named this new hybrid GozNym. The new GozNym hybrid takes the best of both the Nymaim and Gozi ISFB malware to create a powerful Trojan. From the Nymaim malware, it leverages the dropper’s stealth and persistence; the Gozi ISFB parts add the banking Trojan’s capabilities to facilitate fraud via infected Internet browsers. The end result is a new banking Trojan in the wild.


Associated Families

There are currently no families associated with this actor.


References
2019-05-16EuropolEuropol
GOZNYM MALWARE: CYBERCRIMINAL NETWORK DISMANTLED IN INTERNATIONAL OPERATION
GozNym
2016-08-23ThreatpostChris Brook
GozNym Banking Trojan Targeting German Banks
GozNym
2016-04-25Threat PostChris Brook
Attackers Behind GozNym Trojan Set Sights on Europe
GozNym
2016-04-14SecurityIntelligenceLimor Kessem, Lior Keshet
Meet GozNym: The Banking Malware Offspring of Gozi ISFB and Nymaim
ISFB Nymaim GozNym

Credits: MISP Project