There is no confirmed evidence in the cited sources that the original Zeus banking Trojan was distributed through .MSG attachments. Microsoft describes Zeus (also called Zbot) as financial malware spread through phishing and drive-by downloads. A related but distinct malware family, ZLoader, has documented campaigns using malicious Office macros attached to email; that does not establish an MSG-based Zeus campaign.
What Zeus did—and what is known about its delivery
Microsoft describes Zeus, or Zbot, as financial malware designed to steal credentials. Its reported capabilities included capturing keystrokes, intercepting web sessions, and stealing online-banking credentials. Microsoft’s overview identifies phishing and drive-by downloads as delivery routes, but does not document distribution through .MSG attachments. Microsoft’s Zeus overview
Why ZLoader is not proof of an MSG-based Zeus campaign
Microsoft Threat Intelligence says ZLoader was derived from the Zeus banking Trojan, first discovered in 2007. Its April 13, 2022 account describes earlier ZLoader campaigns that delivered malware through malicious Office macros attached to email. Those details concern ZLoader campaigns, not proof that the original Zeus Trojan was sent in MSG files—or that every Zeus-related campaign used the same delivery method. Microsoft Threat Intelligence’s ZLoader analysis
Can a .MSG attachment contain the Zeus banking Trojan?
The available sources do not confirm a Zeus-specific campaign distributed through .MSG attachments. An MSG file is an email-message file format, and its use as a file for submitting email to a security team is not evidence that it was the Trojan’s delivery mechanism. Microsoft’s Defender for Office 365 documentation accepts email files in .MSG or .EML format for analysis. Microsoft’s email submission guidance
#1 Best Overall
Do not treat the filename extension alone as proof that a message is safe or malicious. The important question is whether the message contains suspicious content, such as an unexpected link or attachment, and whether its sender and context can be verified. The cited sources provide no dated primary statistic on the alleged MSG route, so a prevalence or victim count for that claim cannot be substantiated.
What to do with a suspicious email
- Do not interact with it. Microsoft Support advises: “Never click any links or attachments in suspicious emails or Teams messages.” This is general phishing guidance, not a Zeus-specific finding. Microsoft Support’s phishing guidance
- Verify the sender independently. If the message appears to come from someone you know, contact them through a separate channel. If it claims to be from an organization, use contact details you find independently rather than details or links in the message.
- Report and delete it. Microsoft 365 Outlook and Outlook.com users can use the Report phishing control. Follow your workplace’s reporting process if the message arrived at a work account.
What organizations can do in Defender for Office 365
Security staff should distinguish a suspicious message submitted for a verdict from one already confirmed as malicious. Microsoft documents two relevant actions: administrators can submit an email as an .MSG or .EML file for analysis, and they can review phishing or malware campaigns that reached mailboxes and remove malicious messages. The submission format is an operational option; it does not verify the historical claim that Zeus spread through MSG attachments. Microsoft’s campaign review and remediation guide
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

