Gazavat
- Malware type
- backdoor, ddos, trojan, virus
- Family
- Malware family
- Profile updated
- 2026-07-07 14:58:09
Targeted industries: financial-services retail-and-hospitality
Context
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes: - Loading other executables - Load hash cracking plugin - Load DMSniff plugin - Perform webinjection and webfakes - Form grabbing - Command execution - Download file from infected system - Convert infection into proxy - DDOS - Spreading and EXE infecting
Reports & references
- medium.com — Gazavat Expiro Dmsniff Connection And Dga Analysis 8B965Cc0221D (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Gazavat (report)