ISFB
Aliases: Gozi ISFB, IAP, Pandemyia
- First seen
- 2006-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 03:55:48
- Profile updated
- 2026-07-07 12:41:50
Targeted industries: financial-services
Context
2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest. The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version. There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information. ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled. In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim. See win.gozi for additional historical information.
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- securityintelligence.com — Itg23 Crypters Cooperation Between Cybercriminal Groups (report)
- securityintelligence.com — Meet Goznym The Banking Malware Offspring Of Gozi Isfb And Nymaim (report)
- proofpoint.com — Holiday Lull Not So Much (report)
- proofpoint.com — Urlzone Top Malware Japan While Emotet And Line Phishing Round Out Landscape 0 (report)
- proofpoint.com — Threat Actor Profile Ta544 Targets Geographies Italy Japan Range Malware (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- ESET — Eset Threat Report Q22020 (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- Trend Micro — Ursnif Emotet Dridex And Bitpaymer Gangs Linked By A Similar Loader (report)
- labs.sentinelone.com — Enter The Maze Demystifying An Affiliate Involved In Maze Snow (report)
- research.nccgroup.com — Wastedlocker A New Ransomware Variant Developed By The Evil Corp Group (report)
- tgsoft.it — Download (report)
- deepinstinct.com — Deep Dive Packing Software Cryptone (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- threatresearch.ext.hp.com — Detecting Ta551 Domains (report)