The 2019 dismantling of the GozNym network exposed one of the clearest examples of cybercrime becoming organised as a specialist supply chain. Malware developers, forum recruiters, spammers, crypters, bulletproof-hosting providers, account-takeover operators, drop masters and money mules each performed a defined function within the same fraud and laundering operation.
The network infected more than 41,000 computers and was accused of attempting to steal an estimated $100 million, primarily from businesses and financial institutions in the United States and Europe. Its members were recruited through Russian-language underground forums and coordinated their services across several jurisdictions. For a FinCrime audience, the malware was only one component: distribution, infrastructure, credential theft, account access and laundering capacity all had to work together.
A distinction is necessary. GozNym was not principally a conventional software supply-chain attack in which a bank’s trusted vendor or update was compromised to reach downstream customers. It is more accurately understood as a cybercriminal supply chain and an early example of cybercrime as a service. That correction makes the case more useful: it shows how specialist providers can combine into an end-to-end financial-crime operation while illustrating why legitimate institutions must understand their own external dependencies.
Key Takeaways
- GozNym Demonstrated the Industrialisation of Cybercrime
- Banking Malware Can Enable Large-Scale Account Takeover
- Cybercrime Supply Chains Combine Specialised Criminal Services
- Phishing Remains a Critical Initial Access Vector
- Stolen Banking Credentials Can Lead Directly to Financial Loss
- Money Mule Networks Are Essential to Criminal Cash-Out Operations
- Bulletproof Hosting Can Provide Resilient Criminal Infrastructure
- Malware Developers, Spammers and Cashers Can Operate as Separate Specialists
- Cybercrime-as-a-Service Lowers Barriers for Financial Crime
- Third-Party Infrastructure Can Amplify Cyber Risk
- Cyber and Financial Crime Risks Are Increasingly Interconnected
- Criminal Networks Can Operate Across Multiple Jurisdictions
- International Cooperation Is Essential to Disrupting Cybercrime Ecosystems
- Infrastructure Takedowns Can Generate Valuable Financial Intelligence
- Financial Institutions Must Monitor the Entire Attack-to-Cash-Out Journey
Listen the podcast
Watch the video
Why the supply-chain distinction matters
A software supply-chain attack abuses trust in a product, supplier, update mechanism, managed service or software dependency. The target is reached through access inherited from a trusted third party rather than through a direct intrusion.
GozNym operated differently. Its organisers leased malware, recruited specialist criminals, used malicious hosting and distributed phishing emails directly to victims. The Avalanche network was not an innocent supplier secretly compromised by the attackers; it was alleged to be bulletproof infrastructure deliberately provided to cybercriminals.
The relevant supply chain was therefore on the attacker’s side. Defenders should distinguish between an adversary’s commercial ecosystem and compromise propagating through their own vendors, while recognising that both depend on interconnected services and limited visibility across organisational boundaries.
How GozNym combined existing malware capability
GozNym was a hybrid of the Gozi banking Trojan and the Nymaim downloader. The combination brought together code intended to steal banking information with an established mechanism for infecting systems and delivering malicious capability.
The malware was leased rather than used only by its developer. Once sophisticated code can be rented, the creator can monetise it across several campaigns while operational groups avoid the cost and expertise required to build their own banking Trojan.
GozNym captured online-banking credentials from infected computers and passed the information through layers of servers to a central access panel. Account-takeover specialists then used the data to enter victims’ bank accounts and initiate electronic transfers.
The attack crossed several control domains: endpoint compromise became identity compromise; identity compromise became unauthorised access; account access became payment fraud; and payment fraud became money laundering through beneficiary accounts.
Phishing provided the distribution layer
Spammers distributed GozNym through messages designed to resemble legitimate business emails. Malicious links or attachments directed recipients to domains hosting the malware.
Specialisation made this scalable: the spammer did not need to write the malware, and the developer did not need to manage each campaign. Businesses were exposed because employees routinely receive invoices, contracts and document-sharing requests. A message resembling normal correspondence could turn one action into access to the organisation’s banking environment.
Security awareness is necessary, but it cannot carry the whole control burden. Email filtering, attachment isolation, endpoint detection, application control and restrictions on privileged access are needed because convincing messages will sometimes reach users.
Crypters and bulletproof hosting protected the operation
The network used crypters to modify or obfuscate the malware so antivirus products were less likely to detect it. This was another purchasable service designed to extend the malware’s operational life.
Infrastructure came through the Avalanche bulletproof-hosting network. According to the case record, Avalanche served more than 200 cybercriminals and hosted over 20 malware campaigns, including GozNym.
Bulletproof hosting supplies servers, domains and routing intended to resist takedowns and attribution. Several groups can share the same infrastructure while remaining operationally separate. Disrupting one provider can therefore affect many campaigns, making infrastructure intelligence valuable across malware, fraud and AML investigations.
Account-takeover specialists converted data into payments
Captured credentials do not create profit automatically. Someone must identify valuable accounts, overcome additional controls, create payment instructions and react when a bank challenges the activity.
GozNym used specialists who accessed the central panel, entered victims’ online bank accounts and attempted to transfer funds to accounts controlled by other members.
This resembled a commercial operating model: technical teams maintained access, specialists executed transactions and intermediaries received the proceeds. Participants could be replaced without rebuilding the whole network.
Financial institutions should therefore avoid treating malware infection, anomalous login behaviour and beneficiary risk as separate problems. A new session, unusual device, atypical payment and suspicious recipient may be different views of the same attack chain.
Drop masters and money mules completed the chain
Cash-outs or drop masters supplied beneficiary bank accounts. Stolen funds could then be transferred onward or withdrawn by money mules before being distributed to network members.
The malware developer might never touch a victim’s money, while the beneficiary-account controller might have no role in the original infection. The financial system connected them.
Recipient-side monitoring is therefore as important as protecting the compromised payer. Accounts receiving unexpected business transfers, rapidly dispersing funds, sharing devices or beneficiaries, or operating inconsistently with their stated purpose can reveal the cash-out network.
Identifying one mule account may prevent losses across several institutions. That requires timely information sharing, network analytics and investigations focused on relationships rather than isolated payments.
The international takedown matched the network’s structure
The operation involved the United States, Georgia, Ukraine, Moldova, Germany and Bulgaria, supported by Europol and Eurojust. Prosecutions were initiated in four countries, evidence was shared and searches were coordinated against different members of the same network.
That approach was necessary because the organiser, developer, crypter, hosting administrator, spammers and cash-out operators were distributed across jurisdictions. A prosecution confined to the victim country would have addressed only part of the enterprise.
The case also exposed enforcement limits. Several Russia-based defendants remained fugitives, while others were prosecuted where arrest and evidence were available. One takedown does not remove the model, but disruption becomes stronger when authorities target the whole service chain across the locations of suspects, infrastructure and evidence.
What GozNym teaches about genuine third-party risk
Although GozNym was not a classic vendor compromise, the case has a strong parallel with legitimate supply-chain risk. Financial institutions depend on cloud platforms, identity services, payment processors, managed security providers, software libraries and outsourced operations.
A weakness in one provider can create access to many customers or interrupt a critical service at scale. The institution may have strong internal controls while lacking visibility into how a supplier develops software, manages subcontractors, protects privileged access or responds to incidents.
Concentration increases the impact: when many institutions rely on the same provider, component or integration, one compromise can become systemic. Third-party risk must therefore cover the full relationship, including subcontractors, access paths, vulnerabilities and operational dependencies.
What a resilient control stack looks like
The first requirement is dependency visibility. Institutions should maintain an accurate inventory of ICT providers, software components, integrations, data flows and fourth parties supporting critical functions. A software bill of materials can improve component visibility, but it is not proof that the software is secure.
Risk assessment should consider supplier security and institutional dependence. Even a well-secured provider can create concentration risk where no substitute exists. Third-party access should use strong authentication, least privilege, time limits and monitoring, with remote administration segmented from sensitive systems.
Secure-software controls should include code-signing validation, protected build pipelines, dependency scanning and rapid assessment of known exploited vulnerabilities. Updates from trusted vendors should still be monitored for abnormal behaviour because trust is precisely what a supply-chain attacker seeks to exploit.
Contracts should define notification times, audit rights, subcontractor controls, evidence preservation, data return and exit support. Resilience also requires alternatives: institutions should know how to isolate a provider, restore from trusted sources and transition where continued use becomes unsafe.
Detection must connect cyber and financial signals
A supply-chain or malware incident may first appear as an endpoint alert, unusual API call, compromised vendor account or suspicious payment. Separate teams can miss the sequence when signals remain inside cybersecurity, fraud, AML and third-party-risk functions.
FinCrime teams should receive intelligence on compromised credentials, malware infrastructure and supplier incidents affecting customer or corporate accounts. Cyber teams should understand which beneficiary accounts, payment corridors and customer segments are linked to active fraud.
During an incident, institutions should review inherited trust: software updates, service accounts, tokens, integrations and downstream data recipients. Historical transactions may require retrospective analysis once the compromise period is established.
The objective is to identify both the intrusion path and the monetisation path. Closing one without the other leaves either technical persistence or laundering infrastructure intact.
Regulation is moving toward continuous oversight
The Digital Operational Resilience Act has applied to in-scope EU financial entities since January 2025. It requires stronger ICT-risk governance, registers of arrangements with ICT providers and structured management of third-party dependencies.
The direction is clear: outsourcing a service does not outsource accountability. Boards remain responsible for understanding how critical functions depend on external technology and how the institution will respond if that technology is compromised or unavailable.
European assessments show stronger controls alongside continuing concern about deeper dependence and limited supplier visibility. The challenge is converting inventories and contracts into detection and recovery capability.

What this means for financial crime leaders
GozNym should be remembered less as a conventional supplier compromise and more as a blueprint for modular cyber-enabled financial crime. The network assembled specialised services from underground markets and converted them into a complete chain—from malware development and phishing to account takeover and laundering.
For FinCrime leaders, the model has two implications. Criminal activity must be analysed as an ecosystem: the developer, infrastructure provider, account operator and mule network may appear in different datasets but contribute to the same outcome.
Institutions must also examine their own dependencies with similar discipline. A bank’s security is partly determined by the software, credentials, platforms and providers it trusts. Internal controls cannot compensate fully for an unknown dependency or untested recovery plan.
The strongest response connects cyber-threat intelligence, third-party governance, payment monitoring, mule detection and international cooperation. It targets the attacker’s supply chain while reducing the institution’s reliance on invisible or uncontrolled trust.
GozNym demonstrated that cybercrime becomes more scalable when capability is divided into specialist services. Modern financial-crime defence must reverse that advantage by integrating the teams, data and controls that criminals expect to remain separated.
What Financial Institutions Should Consider
- Strengthen Third-Party Cyber Risk Management
- Assess Critical Technology and Service Provider Dependencies
- Integrate Cyber Threat Intelligence With Fraud Monitoring
- Strengthen Phishing and Malware Detection
- Monitor Credential Compromise and Account Takeover Indicators
- Apply Behavioural Analytics Following Suspicious Logins
- Connect Device, Authentication and Transaction Intelligence
- Detect Rapid Beneficiary Creation After Account Compromise
- Strengthen Money Mule and Receiving-Account Detection
- Monitor Rapid Movement of Stolen Funds
- Apply Network Analytics Across Accounts and Beneficiaries
- Integrate Fraud, AML and Cyber Investigation Teams
- Incorporate Malware Intelligence Into Financial Crime Controls
- Conduct Retrospective Reviews Following Infrastructure Takedowns
- Strengthen Third-Party Access and Privileged Account Controls
- Test Business Continuity Against Provider Compromise
- Share Intelligence With Financial Institutions and Law Enforcement
- Treat Cybercrime Infrastructure as Part of the Financial Crime Risk Landscape




The GozNym case demonstrated that modern cybercrime is rarely conducted by one individual or a single criminal group working in isolation. Its success depended on a specialised supply chain in which malware developers, phishing operators, infrastructure providers, account-takeover specialists and money mules each performed a distinct function.
For financial institutions, the case reinforces the need to connect cyber, fraud, AML and payment intelligence. A malware infection, unusual login, suspicious transfer and high-risk beneficiary may appear to be separate incidents, but together they can reveal a coordinated financial-crime operation.
The case also offers a wider lesson for legitimate supply-chain risk. Banks and other regulated organisations increasingly depend on external software, cloud services, identity providers and technology partners. These relationships must be continuously assessed, monitored and incorporated into incident-response and recovery planning.
Ultimately, GozNym showed that criminals gain scale by dividing capability across specialist services. Financial-crime programmes must respond by integrating the teams, data and controls that attackers expect to remain fragmented.