Came across this interesting article on some research into a piece of malware and the forensic techniques used to track down the people responsible, as well as analysing exactly how the Gozi trojan worked and what it did to an infected computer:

http://www.secureworks.com/research/threats/gozi/