Gozi
Aliases: CRM, Gozi CRM, Papras, Snifula, Ursnif
- First seen
- 2006-01-01 00:00:00
- Malware type
- credential-stealer, trojan, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:04:50
- Profile updated
- 2026-07-07 12:55:13
Targeted industries: financial-services
Context
2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka -> Vawtrak/Neverquest In 2006, Gozi v1.0 ('Gozi CRM' aka 'CRM') aka Papras was first observed. It was offered as a CaaS, known as 76Service. This first version of Gozi was developed by Nikita Kurmin, and he borrowed code from Ursnif aka Snifula, a spyware developed by Alexey Ivanov around 2000, and some other kits. Gozi v1.0 thus had a formgrabber module and often is classified as Ursnif aka Snifula. In September 2010, the source code of a particular Gozi CRM dll version was leaked, which led to Vawtrak/Neverquest (in combination with Pony) via Gozi Prinimalka (a slightly modified Gozi v1.0) and Gozi v2.0 (aka 'Gozi ISFB' aka 'ISFB' aka Pandemyia). This version came with a webinject module.
Detection coverage
- 8 YARA rules
Used by threat actors
- TA577 (threat-actor)
- Zloader & Ursnif Affiliate Campaign 2020-22 (campaign)
Detection rules
- CAPE_Ursnifv3 (yara-rule)
- CAPE_Ursnif (yara-rule)
- EMBEERESEARCH_Win_Ursnif_Patterns_Oct_2022 (yara-rule)
- SEKOIA_Ursnif (yara-rule)
- SEKOIA_Ursnif_Ldr4 (yara-rule)
- SIGNATURE_BASE_MAL_Gozicrypter_Dec20_1 (yara-rule)
- MALPEDIA_Win_Gozi_Auto (yara-rule)
- MALPEDIA_Win_Snifula_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Swathmore (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- deepinstinct.com — Deep Dive Packing Software Cryptone (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- Cisco Talos — 2020 Year In Malware (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- Kaspersky — 101638 (report)
- lokalhost.pl — Gozi Tree.Txt (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Gozi (report)
- 0xtoxin.github.io — Gozi Italy Campaign (report)
- blog.malwaremustdie.org — The Infection Of Styx Exploit Kit (report)
- secureworks.com — Gozi (report)
- medium.com — Chapter 1 From Gozi To Isfb The History Of A Mythical Malware Family 82E592577Fef (report)
- 0xtoxin-labs.gitbook.io — Gozi Italian Shellcode Dance (report)
- researchcenter.paloaltonetworks.com — Unit42 Banking Trojans Ursnif Global Distribution Networks Identified (report)
- github.com — Ursnif Beacon Decryptor (report)
- viuleeenz.github.io — Applied Emulation Decrypting Ursnif Strings With Unicorn (report)
- youtube.com — Watch (report)
- blog.gdatasoftware.com — 29325 Analysis Ursnif Spying On Your Data Since 2007 (report)
- r3dy.fr — Gozi Gozi Gozi String Decryption (report)
- therecord.media — Gozi Malware Gang Member Arrested In Colombia (report)
- kostas-ts.medium.com — Ursnif Vs Italy Il Pdf Del Destino 5C83D6281072 (report)