IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its source code with part of the Gozi ISFB source code, creating a combination that is being actively used in attacks against more than 24 U.S. and Canadian banks, stealing millions of dollars so far. X-Force named this new hybrid GozNym. The new GozNym hybrid takes the best of both the Nymaim and Gozi ISFB malware to create a powerful Trojan. From the Nymaim malware, it leverages the dropper’s stealth and persistence; the Gozi ISFB parts add the banking Trojan’s capabilities to facilitate fraud via infected Internet browsers. The end result is a new banking Trojan in the wild.
Executive Summary
GozNym is a sophisticated hybrid banking Trojan combining elements of Nymaim and Gozi ISFB, targeting U.S. and Canadian financial institutions to steal millions in funds. Its integration of stealth persistence mechanisms and banking fraud capabilities makes it a significant threat to the financial sector. IBM X-Force identified its emergence as a critical actor in ongoing financial cybercrime operations.
Goals & Targeting
GozNym’s primary objective is financial exploitation through large-scale banking fraud. It specifically targets financial institutions in the United States and Canada due to their access to high-value financial systems and the potential for significant monetary theft. Operators benefit from the victim’s limited ability to trace transactions, as the malware facilitates stealthy exfiltration of credentials and login sessions. The focus on banks and financial entities underscores a clear intent to monetize infrastructure weaknesses for sustained revenue generation.
Enhanced Description
GozNym represents a convergence of two well-known malware families, Nymaim and Gozi ISFB, recompiled to exploit the strengths of both. This hybrid malware leverages Nymaim’s advanced stealth and persistence techniques, such as dropper-based infection methods, while incorporating Gozi ISFB’s banking Trojan functionalities, including the ability to compromise web browsers and siphon financial credentials. IBM X-Force observed its deployment in sustained attacks against over 24 banks in North America, resulting in substantial financial losses. The malware’s modular architecture enables operators to adapt to defensive measures, making it particularly resilient and effective in targeting financial institutions. This hybrid approach signifies a strategic evolution in cybercriminal tactics, blending persistence and exfiltration capabilities to maximize illicit gains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GozNym operates through sustained campaigns targeting financial institutions, often initiated via spear-phishing emails containing malicious Office documents. Its hybrid nature allows for rapid adaptation to defensive measures, with operators leveraging bulletproof hosting for command-and-control infrastructure. Historical data indicates a focus on North American banks, with operations spanning multiple years and resulting in significant financial losses. The malware’s integration of banking Trojan features suggests a focus on long-term financial exploitation rather than disruptive attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat assessment is based on IBM X-Force’s analysis of the malware’s hybrid architecture and observed targeting patterns, providing high confidence in the actor’s identity and motivations. However, specific MITRE technique mappings and full operational timelines require further confirmation through additional IOC analysis and network telemetry data.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics