/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Banking trojan ZeusVM retrieves configurations hidden inside image files

Hiding in plain sight: a story about a sneaky banking Trojan  —  The Zeus/Zbot Trojan is one the most notorious banking Trojans ever created; it's so popular it gave birth to many offshoots and copycats.

Malwarebytes Unpacked Jerome Segura

Context & Ripple Effects

The Zeus/Zbot codebase has been the most cloned banking trojan of the past decade, and its offshoots keep resetting the detection bar: a botnet tied to this family stole more than $47M from PCs and phones as recently as late 2012, and Gozi's 'improved' variant showed back in 2007 that financial-malware retooling was already an established cycle. Malwarebytes Unpacked's finding that ZeusVM pulls its configuration out of image files extends that lineage from code mutation to concealment of the command layer itself.

The pickup across SC Magazine, Computerworld, and Virus Bulletin on the same day signals that researchers see the technique, not just the family, as the story: if configurations travel as ordinary JPEGs, signature-based scanning of binaries stops being the control point.

First-order effects

  • Bank customers and the financial institutions behind web banking sessions face a harder detection problem right now: antivirus tuned to flag malicious binaries sees only benign image traffic while ZeusVM's operators update behavior server-side by swapping hidden configs.

Second-order effects

  • Security vendors are pushed toward inspecting image payloads and relying on behavioral indicators instead of file signatures, raising the cost of protection for banks that depend on endpoint-only defenses.

Third-order effects

  • If the Zeus copycat pattern holds — many offshoots sharing one proven codebase — takedowns and single-signature fixes lose leverage against a family tree where any knocked-down variant's tricks get inherited by the next fork.

The trend: Banking trojans are shifting evasion from mutating their own binaries to hiding command-and-control data inside innocuous content, moving the arms race away from signature-based defense.