diff --git a/stories/gozi_malware.yml b/stories/gozi_malware.yml index b9d5f9a037..eb6fb2cebf 100644 --- a/stories/gozi_malware.yml +++ b/stories/gozi_malware.yml @@ -11,6 +11,9 @@ narrative: 'Gozi malware, first observed in 2006, has a complex lineage tracing Post-infection activities may include credential theft, lateral movement, and the use of legitimate tools for persistence and remote access. Threat actors often leverage Gozi infections to conduct extensive reconnaissance, move laterally within networks, and potentially prepare for more severe attacks such as data exfiltration or ransomware deployment. /n Detection strategies should focus on identifying suspicious ISO files, unusual process executions (especially involving renamed system utilities), registry modifications, and network communications associated with Gozi''s command and control infrastructure. Additionally, monitoring for post-exploitation activities such as credential dumping, lateral movement attempts, and the deployment of remote management tools can help in early detection and mitigation of Gozi-related threats.' +references: +- https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi +- https://thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/ tags: category: - Adversary Tactics