GOZNYM MALWARE | Dragon News
ID: c11ba177-0091-4afc-87c4-350240867d9c
STIX ID: report--c11ba177-0091-4afc-87c4-350240867d9c
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-06-22
Last Modified Date: 2016-06-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
GozNym is a hybrid Nymaim/Gozi malware campaign observed in March–April 2016 that combines a Nymaim-style loader with Gozi banking trojan functionality; the report lists sample MD5s, domains, C2 IPs, DNS/WHOIS data, and network behaviours (HTTP POST C2, DNS responses that do not match POST destinations), and notes targeting concentrated in the US, Austria and Germany with time-limited samples and active C2 infrastructure.
