# zeustrojancode/Zeus

NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. This repository is for study purposes only, do not message me about your lame hacking attempts.

Repository: https://github.com/zeustrojancode/Zeus
Canonical: https://ross.abutalabs.com/products/zeustrojancode-zeus
Homepage: https://en.wikipedia.org/wiki/Zeus_(malware)
Language: C
License Family: other
Topics: c, c-plus-plus, malware, russian, virus, leaks
Archived: true
Last push: 2020-12-08T10:43:53+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 5591, "days_push": 2094, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1567, forks 698 (observed 2026-08-28T04:05:04.986401+00:00)

## What it is
A GitHub mirror of the leaked source code (version 2.0.8.9) of the Zeus trojan, a notorious Windows banking malware from 2007-2011 that stole credentials via man-in-the-browser keystroke logging and form grabbing. The repository contains no original code from its uploader and exists solely so security researchers can download and study this historically significant malware sample, including its builder and bot configuration tooling.

## Use cases
- study the source code of the Zeus banking trojan
- analyze a historical malware sample for security research
- learn how man-in-the-browser keylogging and form grabbing worked
- build defensive signatures and detection rules from real trojan source
- research botnet architecture and C2 configuration formats
- teach malware analysis with a famous leaked codebase

## When to choose
- You need the authentic leaked Zeus source for malware analysis, forensics, or security training
- You are researching the history and internals of banking trojans and botnets
- You want to derive IOCs or detection signatures from a real malware implementation

## When to avoid
- You intend to run, deploy, or repurpose the code - it is functional malware and doing so is illegal and unethical
- You want maintained, licensed software - there is no license, no active development, and the code reflects 2011-era techniques
- You need a modern security tool or defensive framework rather than a static research artifact

## Facets
- artifact type: application
- maturity: abandoned
- function: security
- domain: security
- platform: windows, c, cpp
- tags: malware, trojan, botnet, keylogger, banking-trojan, zbot, leaked-source-code, malware-analysis, security-research, reverse-engineering, historical-sample, desktop

## Member repositories
- zeustrojancode/Zeus (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:04.986401+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:00:08.184111+00:00, confidence not recorded.
  - readme: https://github.com/zeustrojancode/Zeus (fetched 2026-08-28T04:05:04.986401+00:00, sha c324e5fae740)
  - homepage: https://en.wikipedia.org/wiki/Zeus_(malware) (fetched 2026-08-29T11:28:44.416940+00:00, sha e3e4a08ac24b)
  - site_page: https://en.wikipedia.org/wiki/Wikipedia:About (fetched 2026-08-29T11:28:44.419907+00:00, sha 822f861f7833)
- Data as of 2026-08-30T08:39:29.467469+00:00.
