Gazavat

Malware type
backdoor, ddos, trojan, virus
Family
Malware family
Profile updated
2026-07-07 14:58:09

Targeted industries: financial-services retail-and-hospitality

Context

Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes: - Loading other executables - Load hash cracking plugin - Load DMSniff plugin - Perform webinjection and webfakes - Form grabbing - Command execution - Download file from infected system - Convert infection into proxy - DDOS - Spreading and EXE infecting

Reports & references

  • medium.com — Gazavat Expiro Dmsniff Connection And Dga Analysis 8B965Cc0221D (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gazavat (report)

External references