Gozi

Aliases: CRM, Gozi CRM, Papras, Snifula, Ursnif

First seen
2006-01-01 00:00:00
Malware type
credential-stealer, trojan, spyware
Family
Malware family
Last IoC activity
2026-07-22 04:04:50
Profile updated
2026-07-07 12:55:13

Targeted industries: financial-services

Context

2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka -> Vawtrak/Neverquest In 2006, Gozi v1.0 ('Gozi CRM' aka 'CRM') aka Papras was first observed. It was offered as a CaaS, known as 76Service. This first version of Gozi was developed by Nikita Kurmin, and he borrowed code from Ursnif aka Snifula, a spyware developed by Alexey Ivanov around 2000, and some other kits. Gozi v1.0 thus had a formgrabber module and often is classified as Ursnif aka Snifula. In September 2010, the source code of a particular Gozi CRM dll version was leaked, which led to Vawtrak/Neverquest (in combination with Pony) via Gozi Prinimalka (a slightly modified Gozi v1.0) and Gozi v2.0 (aka 'Gozi ISFB' aka 'ISFB' aka Pandemyia). This version came with a webinject module.

Detection coverage

  • 8 YARA rules

Used by threat actors

  • TA577 (threat-actor)
  • Zloader & Ursnif Affiliate Campaign 2020-22 (campaign)

Detection rules

  • CAPE_Ursnifv3 (yara-rule)
  • CAPE_Ursnif (yara-rule)
  • EMBEERESEARCH_Win_Ursnif_Patterns_Oct_2022 (yara-rule)
  • SEKOIA_Ursnif (yara-rule)
  • SEKOIA_Ursnif_Ldr4 (yara-rule)
  • SIGNATURE_BASE_MAL_Gozicrypter_Dec20_1 (yara-rule)
  • MALPEDIA_Win_Gozi_Auto (yara-rule)
  • MALPEDIA_Win_Snifula_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Swathmore (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • deepinstinct.com — Deep Dive Packing Software Cryptone (report)
  • mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • Kaspersky — 101638 (report)
  • lokalhost.pl — Gozi Tree.Txt (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gozi (report)
  • 0xtoxin.github.io — Gozi Italy Campaign (report)
  • blog.malwaremustdie.org — The Infection Of Styx Exploit Kit (report)
  • secureworks.com — Gozi (report)
  • medium.com — Chapter 1 From Gozi To Isfb The History Of A Mythical Malware Family 82E592577Fef (report)
  • 0xtoxin-labs.gitbook.io — Gozi Italian Shellcode Dance (report)
  • researchcenter.paloaltonetworks.com — Unit42 Banking Trojans Ursnif Global Distribution Networks Identified (report)
  • github.com — Ursnif Beacon Decryptor (report)
  • viuleeenz.github.io — Applied Emulation Decrypting Ursnif Strings With Unicorn (report)
  • youtube.com — Watch (report)
  • blog.gdatasoftware.com — 29325 Analysis Ursnif Spying On Your Data Since 2007 (report)
  • r3dy.fr — Gozi Gozi Gozi String Decryption (report)
  • therecord.media — Gozi Malware Gang Member Arrested In Colombia (report)
  • kostas-ts.medium.com — Ursnif Vs Italy Il Pdf Del Destino 5C83D6281072 (report)

External references