GozNym is a banking Trojan hybrid from Nymaim and Gozi ISFB targeting US and Canadian bank customers.
Analyst brief
GozNym is a banking Trojan hybrid combining the Nymaim and Gozi ISFB malware. It primarily targets customers of more than 24 banks in the U.S. and Canada. The threat leverages Nymaim's stealth and persistence for dropper functions with Gozi's web injection capabilities to facilitate browser-based fraud. Defenders should focus on multi-factor authentication enforcement, monitoring network traffic for Gozi-related C2 indicators, and investigating signs of Nymaim activity like VBScript/WMI abuse for persistence.
GozNym
unknown
IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its source code with part of the Gozi ISFB source code, creating a combination that is being actively used in attacks against more than 24 U.S. and Canadian banks, stealing millions of dollars so far. X-Force named this new hybrid GozNym. The new GozNym hybrid takes the best of both the Nymaim and Gozi ISFB malware to create a powerful Trojan. From the Nymaim malware, it leverages the dropper’s stealth and persistence; the Gozi ISFB parts add the banking Trojan’s capabilities to facilitate fraud via infected Internet browsers. The end result is a new banking Trojan in the wild.