logo

GOZNYM MALWARE | Dragon News

ID: c11ba177-0091-4afc-87c4-350240867d9c

STIX ID: report--c11ba177-0091-4afc-87c4-350240867d9c

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-06-22

Last Modified Date: 2016-06-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
GozNym is a hybrid Nymaim/Gozi malware campaign observed in March–April 2016 that combines a Nymaim-style loader with Gozi banking trojan functionality; the report lists sample MD5s, domains, C2 IPs, DNS/WHOIS data, and network behaviours (HTTP POST C2, DNS responses that do not match POST destinations), and notes targeting concentrated in the US, Austria and Germany with time-limited samples and active C2 infrastructure.