GOLD EVERGREEN is a financially motivated cybercriminal group known for orchestrating global banking fraud through the Gameover Zeus botnet.
Analyst brief
GOLD EVERGREEN was a financially motivated cybercriminal group that operated the Gameover Zeus botnet until June 2014, orchestrating large-scale banking fraud. The group primarily targeted financial institutions and individual bank accounts worldwide. Their TTPs relied on the Zeus, JabberZeus, and Gameover Zeus malware families to build P2P botnets, with the primary malware developer and operator being Russian national Evgeniy Bogachev. Defenders should focus on detecting banking trojan activity, enforcing multi-factor authentication, and monitoring for DGA-based C2 traffic associated with Gameover Zeus.
GOLD EVERGREEN
unknown
GOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompasses an expansive and long running criminal conspiracy operated by a confederation of individuals calling themselves The Business Club from the mid 2000s until 2014. GOLD EVERGREEN's technical operation was facilitated primarily through botnets using the Zeus, JabberZeus, and eventually Gameover Zeus malware families. These malware families were designed and maintained by a Russian national Evgeniy Bogachev (aka 'slavik') who was indicted by the U.S. DOJ in 2014 and remains a fugitive.
Which primary malware families did GOLD EVERGREEN use to build botnets?+
GOLD EVERGREEN primarily used the Zeus, JabberZeus, and Gameover Zeus malware families to build peer-to-peer based botnets.
What defensive measures should be taken against activity associated with the Gameover Zeus botnet?+
Defenders should focus on detecting banking trojan activity, enforcing multi-factor authentication, and monitoring for DGA-based C2 traffic associated with Gameover Zeus.