C&CMembers
C&C

Decade-Old GameOver Zeus DGA Signature Still Catching Live Malware

A 13KB courier-notice loader trips a 2014-era Snort rule for GameOver Zeus ten times over, tying back to a larger unsigned Zeus/ZBot binary through nothing but a shared PEiD packer. Nearby domain infrastructure shows certificates reissued within the past two weeks, but the two layers are never shown to be directly connected.

Sep 13, 2026, 15:00 (UTC+9)Last seenSep 13, 2026Severity100ByCTX TeamIOC33MITRE16RegionsRO

Ten Snort and Emerging Threats alerts fired against a 13-kilobyte Windows executable disguised as a courier tracking notice — five of them the exact same rule, "MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected." That rule was written for GameOver Zeus, the peer-to-peer variant of the Zeus banking trojan that law enforcement spent years trying to dismantle starting in 2014.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence