SpyEye
- First seen
- 2009-01-01 00:00:00
- Malware type
- trojan, keylogger, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-06-27 03:32:05
- Profile updated
- 2026-07-07 14:47:49
Targeted industries: financial-services
Context
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Spyeye (yara-rule)
- MALPEDIA_Win_Spyeye_Auto (yara-rule)
Reports & references
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- Kaspersky — 101638 (report)
- justice.gov — Four Individuals Plead Guilty Rico Conspiracy Involving Bulletproof Hosting Cybercriminals (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Spyeye (report)
- krebsonsecurity.com — Spyeye Vs Zeus Rivalry (report)
- malwareint.blogspot.com — Spyeye Bot Part Two Conversations With (report)
- krebsonsecurity.com — Spyeye Botnets Bogus Billing Feature (report)
- computerworld.com — Spyeye Trojan Defeating Online Banking Defenses (report)
- krebsonsecurity.com — Spyeye Targets Opera Google Chrome Users (report)
- sans.org — Clash Titans Zeus Spyeye 33393 (report)
- pcworld.com — Spyeye Malware Borrows Zeus Trick To Mask Fraud (report)
- Broadcom/Symantec — Spyeye Bot Versus Zeus Bot (report)
- Microsoft — Malware Encyclopedia Description (report)