Netskope Threat Labs

Gozi

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Gozi is a banking trojan lineage that began as a spyware family around 2000 and grew through leaked source code into multiple strains. The 2006 Gozi CRM version operated as a crimeware service, and the leak of its code in 2010 produced Gozi ISFB with web inject modules as well as the Vawtrak and NeverQuest botnets. Detections under this name can therefore represent several related code bases that share a common origin.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Infostealer.Gozi
Script-Macro.Downloader.Gozi
Script-Macro.Trojan.Gozi
Trojan.URL.Gozi.B
Win32.Infostealer.Gozi
Win32.Trojan.Gozi
Win64.Infostealer.Gozi
Win64.Trojan.Gozi