DreamBot
- First seen
- 2014-01-01 00:00:00
- Malware type
- credential-stealer, trojan, botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-21 15:57:45
- Profile updated
- 2026-07-07 13:45:14
Targeted industries: financial-services
Context
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) 2014 Dreambot (Gozi ISFB variant) In 2014, a variant of Gozi ISFB was developed. Mainly, the dropper performs additional anti-vm checks (vmware, vbox, qemu), while the actual bot-dll remains unchanged in most parts. New functionality, such as TOR support, was added though and often, the Fluxxy fast-flux network is used. See win.gozi for additional historical information.
Detection coverage
- 1 YARA rules
Detection rules
- CAPE_Dreambot (yara-rule)
Reports & references
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- community.riskiq.com — 30F22A00 (report)
- youtube.com — Watch (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dreambot (report)
- medium.com — Installcapital When Adware Becomes Pay Per Install Cyber Crime 15516249A451 (report)
- proofpoint.com — Ursnif Variant Dreambot Adds Tor Functionality (report)
- research.checkpoint.com — Gozi The Malware With A Thousand Faces (report)
- medium.com — The End Of Dreambot A Loved Piece Of Gozi 24Cc9Bfc8122 (report)
- lokalhost.pl — Gozi Tree.Txt (report)