GOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompasses an expansive and long running criminal conspiracy operated by a confederation of individuals calling themselves The Business Club from the mid 2000s until 2014. GOLD EVERGREEN's technical operation was facilitated primarily through botnets using the Zeus, JabberZeus, and eventually Gameover Zeus malware families. These malware families were designed and maintained by a Russian national Evgeniy Bogachev (aka 'slavik') who was indicted by the U.S. DOJ in 2014 and remains a fugitive.
Executive Summary
GOLD EVERGREEN was a financially motivated cybercriminal group responsible for operating the Gameover Zeus botnet until 2014. The group, also known as The Business Club, utilized advanced malware families like Zeus and JabberZeus to conduct large-scale banking fraud. Its operations were orchestrated by Evgeniy Bogachev, a Russian national indicted by the U.S. DOJ in 2014.
Goals & Targeting
GOLD EVERGREEN's primary objective was to exploit financial institutions and individuals to monetize stolen data through banking fraud, ransomware, and the sale of sensitive information. The group targeted sectors with high-value financial assets, including banks, payment processors, and individuals using online banking services. Its operations focused on countries with widespread internet adoption and lax cybersecurity measures, including the United States, Europe, and parts of Asia. The group's sustained presence in the cybercriminal ecosystem suggests a strategic intent to maximize returns through large-scale, prolonged attacks.
Enhanced Description
GOLD EVERGREEN operated as a long-running criminal enterprise from the mid-2000s until 2014, leveraging botnets to steal financial data from individuals and institutions. The group's primary malware included Zeus, JabberZeus, and Gameover Zeus, with the latter incorporating peer-to-peer (P2P) communication to evade detection. Gameover Zeus, in particular, was notable for its decentralized architecture and use of domain generation algorithms (DGAs) to maintain command-and-control infrastructure. The group's activities were led by Evgeniy Bogachev, who was indicted by the U.S. Department of Justice in 2014 for his role in the botnet's operation and remains a fugitive. The group's dissolution in 2014 followed coordinated law enforcement actions, including the seizure of infrastructure and the disruption of the botnet's operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD EVERGREEN's campaigns spanned over a decade, with a focus on sustained botnet operations and financial exploitation. The group's use of P2P communication in Gameover Zeus marked a significant evolution in botnet design, enhancing resilience against law enforcement takedowns. Campaigns often involved targeted phishing to establish initial access, followed by malware deployment to compromise systems and exfiltrate financial data. Notable operations include the large-scale disruption of Gameover Zeus in 2014, which involved international cooperation and led to Bogachev's indictment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the group's historical activities, malware associations, and targeting profile based on DOJ indictments and threat intelligence reports. However, gaps exist in confirmed operational details post-2014 and the group's current status. The sophistication of their techniques and the scale of their botnets are well-documented, but attribution to specific individuals beyond Bogachev remains uncertain.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics