SpyEye

First seen
2009-01-01 00:00:00
Malware type
trojan, keylogger, credential-stealer
Family
Malware family
Last IoC activity
2026-06-27 03:32:05
Profile updated
2026-07-07 14:47:49

Targeted industries: financial-services

Context

SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Spyeye (yara-rule)
  • MALPEDIA_Win_Spyeye_Auto (yara-rule)

Reports & references

  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • Kaspersky — 101638 (report)
  • justice.gov — Four Individuals Plead Guilty Rico Conspiracy Involving Bulletproof Hosting Cybercriminals (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Spyeye (report)
  • krebsonsecurity.com — Spyeye Vs Zeus Rivalry (report)
  • malwareint.blogspot.com — Spyeye Bot Part Two Conversations With (report)
  • krebsonsecurity.com — Spyeye Botnets Bogus Billing Feature (report)
  • computerworld.com — Spyeye Trojan Defeating Online Banking Defenses (report)
  • krebsonsecurity.com — Spyeye Targets Opera Google Chrome Users (report)
  • sans.org — Clash Titans Zeus Spyeye 33393 (report)
  • pcworld.com — Spyeye Malware Borrows Zeus Trick To Mask Fraud (report)
  • Broadcom/Symantec — Spyeye Bot Versus Zeus Bot (report)
  • Microsoft — Malware Encyclopedia Description (report)

External references