GozNym is a hybrid creation specifically coded to, among other things, avoid detection by legacy AV solutions. The gang had combined the Nymaim malware, a first stage loader with persistence capabilities, with a second-stage infection containing a version of the Gozi ISFB banking trojan, hence the name GozNym. Read More: https://www.sentinelone.com/blog/goznym-banking-malware-gang-busted/
Nymaim has been around for several years but is notable for its ability to avoid security solutions. As previous researchers have revealed, Nymaim checks for running processes that belong to certain AV vendor products.
See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.