DreamBot

First seen
2014-01-01 00:00:00
Malware type
credential-stealer, trojan, botnet
Family
Malware family
Last IoC activity
2026-07-21 15:57:45
Profile updated
2026-07-07 13:45:14

Targeted industries: financial-services

Context

2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) 2014 Dreambot (Gozi ISFB variant) In 2014, a variant of Gozi ISFB was developed. Mainly, the dropper performs additional anti-vm checks (vmware, vbox, qemu), while the actual bot-dll remains unchanged in most parts. New functionality, such as TOR support, was added though and often, the Fluxxy fast-flux network is used. See win.gozi for additional historical information.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Dreambot (yara-rule)

Reports & references

  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • community.riskiq.com — 30F22A00 (report)
  • youtube.com — Watch (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dreambot (report)
  • medium.com — Installcapital When Adware Becomes Pay Per Install Cyber Crime 15516249A451 (report)
  • proofpoint.com — Ursnif Variant Dreambot Adds Tor Functionality (report)
  • research.checkpoint.com — Gozi The Malware With A Thousand Faces (report)
  • medium.com — The End Of Dreambot A Loved Piece Of Gozi 24Cc9Bfc8122 (report)
  • lokalhost.pl — Gozi Tree.Txt (report)

External references