Overview
Zeus stole credentials by injecting HTML into banking sessions and grabbing cookies directly from the browser.\nIts source leak in 2011 spawned dozens of successors and industrialised fraud against online banking.\nThe architecture, a signed binary with a pluggable configuration, became the template for modern stealers.
Indicators of Compromise
Signals that suggest this is present on a system.
- Injected form fields on banking origins
- Certificate store entries added by an unknown publisher
- Config files referencing new target institutions