Gameover P2P

Aliases: GOZ, Gameover ZeuS, Mapp, ZeuS P2P

First seen
2011-09-01 00:00:00
Malware type
botnet, credential-stealer, ransomware, trojan
Family
Malware family
Profile updated
2026-07-07 12:36:00

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:ru country_code:uk

Context

Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan. According to a report by Symantec, Gameover Zeus has largely been used for banking fraud and distribution of the CryptoLocker ransomware. In early June 2014, the U.S. Department of Justice announced that an international inter-agency collaboration named Operation Tovar had succeeded in temporarily cutting communication between Gameover ZeuS and its command and control servers.

Reports & references

  • web.archive.org — Security Vendors Take Action Against Hidden Lynx Malware (report)
  • krebsonsecurity.com — Inside Evil Corp A 100M Cybercrime Menace (report)
  • secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • web.archive.org — Globalthreatintelreport (report)
  • go.recordedfuture.com — Cta 2021 0909 (report)
  • justice.gov — Us Leads Multi National Action Against Gameover Zeus Botnet And Cryptolocker Ransomware (report)
  • intel471.com — Cybercrime Russia China Iran Nation State (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gameover P2P (report)
  • cert.pl — 2013 06 P2P Rap En (report)
  • bin.re — Three Variants Of Murofets Dga (report)
  • wired.com — Russian Hacker Spy Botnet (report)
  • wired.com (report)
  • blackhat.com — Us 15 Peterson Gameover Zeus Badguys And Backends (report)
  • nbviewer.org — Gameover%20Version%202014 05 28.Ipynb (report)
  • syssec-project.eu — Zeus Malware13 (report)
  • lawfareblog.com — What Point These Nation State Indictments (report)

External references