New version of ZeuS malware has targeted over 150 banks and 20 payment systems worldwide
Charlie Osborne / ZDNet :
Context & Ripple Effects
This ZDNet report on a new ZeuS variant hitting 150+ banks lands in the middle of a run of banking-trojan escalations: weeks later Kaspersky attributed at least $300M in thefts across 100+ financial institutions in 30 nations to a sophisticated campaign dating back to late 2013, suggesting the same wave of institution-targeting malware rather than isolated hits.
The aftermath is already documented in the related coverage — a US-UK-EU shutdown of Dridex, which had taken $31M from UK accounts, then the emergence of GozNym, a hybrid of Nymaim and Gozi, showing the codebase and crew lineages these families share.
First-order effects
- Over 150 banks and 20 payment systems worldwide face immediate fraud exposure from the variant's account-credential theft, forcing incident-response and re-issuance costs onto those institutions right now.
- Security vendors and financial CERTs must add signatures and behavioral detections for this specific build, since each new ZeuS iteration resets the detection baseline.
Second-order effects
- Sustained thefts on this scale pull in multinational law enforcement, as later happened with the Dridex botnet takedown — coordinated operations become the standard counter-move rather than vendor patching alone.
- Banking malware families begin cross-breeding and code-sharing, as GozNym's Nymaim-plus-Gozi hybrid demonstrates, because successful variants like ZeuS seed an ecosystem of derivatives.
Third-order effects
- If the pattern holds, banking trojans consolidate into organized criminal enterprises with identifiable operators — the DOJ's indictment of 10 GozNym-network members over an estimated $100M in attempted thefts marks the shift from anonymous malware to prosecutable organizations.
- Financial institutions' defense posture structurally shifts toward shared threat intelligence and cross-border police cooperation, since single-bank perimeter defenses demonstrably fail against campaigns spanning dozens of countries.
The trend: Banking trojans are maturing from commodity credential stealers into organized criminal networks whose scale eventually draws multinational law-enforcement takedowns.