logo

We see you, Gozi

ID: ef716abc-8598-5dc0-ae08-a5a640f78d5c

STIX ID: report--ef716abc-8598-5dc0-ae08-a5a640f78d5c

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2022-06-24

Date Updated: 2026-04-27

...
...

This report analyzes a June 2022 sample of the ISFB/Gozi banking Trojan, detailing a multi-stage in-memory kill chain where an initial self-extracting EXE launches a .NET downloader, which fetches an obfuscated .NET packer from a Discord CDN via a URL shortener; the packer decrypts and unpacks a Gozi downloader DLL that attempts to contact C2 servers to retrieve the main module. The write-up includes a high-level breakdown of each stage, the Gozi downloader configuration, and IOCs (file hashes, filenames, and network URLs) observed during the investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.