Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GozNym

Description

IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its source code with part of the Gozi ISFB source code, creating a combination that is being actively used in attacks against more than 24 U.S. and Canadian banks, stealing millions of dollars so far. X-Force named this new hybrid GozNym. The new GozNym hybrid takes the best of both the Nymaim and Gozi ISFB malware to create a powerful Trojan. From the Nymaim malware, it leverages the dropper’s stealth and persistence; the Gozi ISFB parts add the banking Trojan’s capabilities to facilitate fraud via infected Internet browsers. The end result is a new banking Trojan in the wild.

AI Analysis

· 1 week ago

Executive Summary

GozNym is a sophisticated hybrid banking Trojan combining elements of Nymaim and Gozi ISFB, targeting U.S. and Canadian financial institutions to steal millions in funds. Its integration of stealth persistence mechanisms and banking fraud capabilities makes it a significant threat to the financial sector. IBM X-Force identified its emergence as a critical actor in ongoing financial cybercrime operations.

Goals & Targeting

GozNym’s primary objective is financial exploitation through large-scale banking fraud. It specifically targets financial institutions in the United States and Canada due to their access to high-value financial systems and the potential for significant monetary theft. Operators benefit from the victim’s limited ability to trace transactions, as the malware facilitates stealthy exfiltration of credentials and login sessions. The focus on banks and financial entities underscores a clear intent to monetize infrastructure weaknesses for sustained revenue generation.

Enhanced Description

GozNym represents a convergence of two well-known malware families, Nymaim and Gozi ISFB, recompiled to exploit the strengths of both. This hybrid malware leverages Nymaim’s advanced stealth and persistence techniques, such as dropper-based infection methods, while incorporating Gozi ISFB’s banking Trojan functionalities, including the ability to compromise web browsers and siphon financial credentials. IBM X-Force observed its deployment in sustained attacks against over 24 banks in North America, resulting in substantial financial losses. The malware’s modular architecture enables operators to adapt to defensive measures, making it particularly resilient and effective in targeting financial institutions. This hybrid approach signifies a strategic evolution in cybercriminal tactics, blending persistence and exfiltration capabilities to maximize illicit gains.

Key Capabilities

  • Stealthy persistence mechanisms using droppers and process injection
  • Browser-based credential theft and form-filling capabilities
  • Evasion of endpoint detection through code obfuscation
  • Command-and-control (C2) communication over encrypted channels
  • Modular payload execution for adaptive attacks
  • Phishing-driven initial compromise via malicious document delivery

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration

ATT&CK Techniques

T1059.003
T1132.001
T1566.001
T1040
T1055.001
T1560.001

Software / Tooling

Nymaim
Gozi ISFB
Custom Hybrid Dropper

Campaigns & Victims

GozNym operates through sustained campaigns targeting financial institutions, often initiated via spear-phishing emails containing malicious Office documents. Its hybrid nature allows for rapid adaptation to defensive measures, with operators leveraging bulletproof hosting for command-and-control infrastructure. Historical data indicates a focus on North American banks, with operations spanning multiple years and resulting in significant financial losses. The malware’s integration of banking Trojan features suggests a focus on long-term financial exploitation rather than disruptive attacks.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over DNS or HTTPS using fast-flux infrastructure
  • Staging of payloads on bulletproof hosting services
  • Suspicious registry modifications for persistence
  • Unusual browser process injection patterns

Recommended Actions

  • Implement advanced email filtering to detect macro-laced phishing documents
  • Monitor for suspicious DNS queries and encrypted C2 traffic patterns
  • Deploy endpoint detection tools capable of identifying process injection and behavioral anomalies
  • Conduct regular employee training on phishing recognition and incident reporting
  • Isolate and investigate systems with abnormal login activity or financial transaction patterns
  • Collaborate with financial sector threat intelligence sharing groups for real-time IOC updates

Suggested Tags

APT
banking-malware
financial-sector
phishing
hybrid-malware

Confidence Assessment

The threat assessment is based on IBM X-Force’s analysis of the malware’s hybrid architecture and observed targeting patterns, providing high confidence in the actor’s identity and motivations. However, specific MITRE technique mappings and full operational timelines require further confirmation through additional IOC analysis and network telemetry data.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
banking-malware
financial-sector
phishing
hybrid-malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.