logo

A Look At The New Gameover Zeus Variant

ID: d3c4b535-1a9e-5ab7-b896-d7adaeab85d0

STIX ID: report--d3c4b535-1a9e-5ab7-b896-d7adaeab85d0

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes a July 2014 resurgence of a Gameover Zeus (Zbot) banking-Trojan variant distributed via Cutwail spam attachments that download the payload, drop and run epoxs.exe from a Temp subfolder, create persistence via HKCU Run, inject into system processes and use a DGA with fast-flux C2 infrastructure to retrieve banking web-inject configurations. The analysis documents infection workflow, sample DGA domains, dropped batch cleanup behavior, and notes a reduction in resilience compared to prior P2P-enabled and rootkit-equipped variants while infections remain relatively low.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.