Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD EVERGREEN

Description

GOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompasses an expansive and long running criminal conspiracy operated by a confederation of individuals calling themselves The Business Club from the mid 2000s until 2014. GOLD EVERGREEN's technical operation was facilitated primarily through botnets using the Zeus, JabberZeus, and eventually Gameover Zeus malware families. These malware families were designed and maintained by a Russian national Evgeniy Bogachev (aka 'slavik') who was indicted by the U.S. DOJ in 2014 and remains a fugitive.

AI Analysis

· 1 week ago

Executive Summary

GOLD EVERGREEN was a financially motivated cybercriminal group responsible for operating the Gameover Zeus botnet until 2014. The group, also known as The Business Club, utilized advanced malware families like Zeus and JabberZeus to conduct large-scale banking fraud. Its operations were orchestrated by Evgeniy Bogachev, a Russian national indicted by the U.S. DOJ in 2014.

Goals & Targeting

GOLD EVERGREEN's primary objective was to exploit financial institutions and individuals to monetize stolen data through banking fraud, ransomware, and the sale of sensitive information. The group targeted sectors with high-value financial assets, including banks, payment processors, and individuals using online banking services. Its operations focused on countries with widespread internet adoption and lax cybersecurity measures, including the United States, Europe, and parts of Asia. The group's sustained presence in the cybercriminal ecosystem suggests a strategic intent to maximize returns through large-scale, prolonged attacks.

Enhanced Description

GOLD EVERGREEN operated as a long-running criminal enterprise from the mid-2000s until 2014, leveraging botnets to steal financial data from individuals and institutions. The group's primary malware included Zeus, JabberZeus, and Gameover Zeus, with the latter incorporating peer-to-peer (P2P) communication to evade detection. Gameover Zeus, in particular, was notable for its decentralized architecture and use of domain generation algorithms (DGAs) to maintain command-and-control infrastructure. The group's activities were led by Evgeniy Bogachev, who was indicted by the U.S. Department of Justice in 2014 for his role in the botnet's operation and remains a fugitive. The group's dissolution in 2014 followed coordinated law enforcement actions, including the seizure of infrastructure and the disruption of the botnet's operations.

Key Capabilities

  • Deployment of advanced botnets (Zeus, JabberZeus, Gameover Zeus)
  • Use of peer-to-peer (P2P) communication for decentralized command-and-control (C2)
  • Sophisticated spear-phishing campaigns with malicious Office documents
  • Implementation of domain generation algorithms (DGAs) for C2 infrastructure resilience
  • Custom tool development for malware distribution and financial data exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration

ATT&CK Techniques

T1059.003
T1055.001
T1112.001
T1566.001
T1071.001

Software / Tooling

Zeus
JabberZeus
Gameover Zeus
Custom C2 infrastructure tools
Malicious Office documents (macro-laced)

Campaigns & Victims

GOLD EVERGREEN's campaigns spanned over a decade, with a focus on sustained botnet operations and financial exploitation. The group's use of P2P communication in Gameover Zeus marked a significant evolution in botnet design, enhancing resilience against law enforcement takedowns. Campaigns often involved targeted phishing to establish initial access, followed by malware deployment to compromise systems and exfiltrate financial data. Notable operations include the large-scale disruption of Gameover Zeus in 2014, which involved international cooperation and led to Bogachev's indictment.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 traffic over P2P networks
  • Botnet command server domains
  • Domain generation algorithm (DGA) patterns
  • Malicious configuration files for Zeus variants

Recommended Actions

  • Implement advanced email filtering to block macro-laced phishing attempts
  • Deploy network-based intrusion detection systems to monitor for P2P C2 traffic
  • Use endpoint detection and response (EDR) tools to identify Zeus and Gameover Zeus variants
  • Conduct regular employee training on recognizing social engineering tactics
  • Monitor domain registrations for signs of DGA usage or botnet infrastructure

Suggested Tags

APT
financialcrime
botnet
bankingmalware
Russia

Confidence Assessment

High confidence in the group's historical activities, malware associations, and targeting profile based on DOJ indictments and threat intelligence reports. However, gaps exist in confirmed operational details post-2014 and the group's current status. The sophistication of their techniques and the scale of their botnets are well-documented, but attribution to specific individuals beyond Bogachev remains uncertain.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

DDoS
APT
financialcrime
botnet
bankingmalware
Russia

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.