Dyre

MITRE ATT&CK: S0024 View on attack.mitre.org

Aliases: Dyzap, Dyreza, Dyre

First seen
2014-06-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
2081 (1985 malicious)
Last IoC activity
2026-09-02 00:41:23
Profile updated
2026-07-07 15:44:05

Targeted industries: financial-services

Targeted regions: country_code:us country_code:gb country_code:de

Context

Dyre is a banking Trojan that has been used for financial gain.

Recent IoC activity

1,994 malicious indicators in Maltiverse are attributed to Dyre (S0024). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname wfa9c32bd9801642e597961af1ce880a1f.to 2026-09-03 1
hostname l9088ac67808583eb04cdd930a1050305e.ws 2026-09-03 1
hostname m2ddbc1e67483a8610ad799eb80e63b6ba.to 2026-09-03 1
hostname vce8e20c13129c41902705f76986097d20.ws 2026-09-03 1
hostname ka994810a5de747465f281c630eae029ef.to 2026-09-02 1
hostname q913680c87011213316111f5a94632a650.to 2026-09-02 1
hostname g1f2f29206ae5ebd21c370f0e1ab0aaa32.to 2026-09-02 1
hostname avandogl.com 2026-09-02 1
hostname la15e23e4028955ea9c769d13f03ba7289.ws 2026-09-02 1
hostname t373fbb3fa695e107bb51ff33b14eb3567.ws 2026-09-02 1
hostname r2dab5f0f559b89c2e9d40cc43fe9a0372.ws 2026-09-02 1
hostname zd46223f39adab42253385cd89cb33ee57.ws 2026-09-02 1
hostname hd91584f68dfde04e7c8b58fd8888b5fd7.ws 2026-09-02 1
hostname b0565a4fbf297428ea742ec1b8698436c2.ws 2026-09-02 1
hostname z271499749580d528cf17d23d0564b4362.ws 2026-09-02 1
hostname q03abbda8eae8c95d188be87cb35874f6e.to 2026-09-02 1
hostname lf53abef67ee25c690a62d5961cc1cc332.ws 2026-09-01 1
hostname sd664da716c534590573343cfa61dd3a4a.to 2026-09-01 1
hostname f73d75d9d17f8240a0147c147e10ff4632.ws 2026-09-01 1
hostname y51f62af5f1f6bb9031ad78542009b7355.to 2026-09-01 1

Detection coverage

  • 1 YARA rules
  • 306 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Process Injection (attack-pattern)
  • Software Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • System Service Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Dyre_Auto (yara-rule)

Reports & references

  • CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
  • secureworks.com — Dyre Banking Trojan (report)
  • secureworks.com — Gold Blackburn (report)
  • secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
  • secureworks.com — Gold Blackburn (report)
  • research.checkpoint.com — Graphology Of An Exploit Playbit (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • blueliv.com — Network Insights Of Dyre And Dridex Trojan Bankers (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dyre (report)
  • blog.malwarebytes.com — A Technical Look At Dyreza (report)
  • Mandiant — Dyre Banking Trojan (report)
  • forbes.com — Dyre Hackers Stealing Millions From American Coporates (report)
  • Broadcom/Symantec — Dyre Emerging Threat (report)
  • MITRE ATT&CK — S0024 (report)
  • nakedsecurity.sophos.com — Notes From Sophoslabs Dyreza The Malware That Discriminates Against Old Computers (report)

External references