ZeroAccess, also widely known as Sirefef, ZAccess, Max++, and Smiscer, is a Windows malware family best known as a sophisticated peer-to-peer botnet and rootkit-enabled crimeware platform. First observed around 2009–2010, it initially functioned as a stealthy delivery mechanism for additional malware, including fake antivirus payloads, and later evolved into a large-scale monetization platform primarily used for click fraud and cryptocurrency mining. At its peak, it infected millions of systems globally and maintained a very large active bot population.
Early ZeroAccess variants used advanced stealth techniques associated with rootkits, including hidden storage areas, abuse of NTFS metadata such as alternate data streams and Extended Attributes, concealed components under recycle-bin themed locations, and kernel-mode components that hindered detection and removal. Some variants injected code into legitimate Windows processes and established persistence through multiple startup methods. Later versions reportedly shifted away from kernel-mode components and operated largely in user-mode memory while retaining resilient botnet functionality.
ZeroAccess used an encrypted peer-to-peer command-and-control architecture designed for robustness, rapid propagation of peer information, and distribution of plugin modules or additional payloads. The malware could receive instructions to download further malware, support click-fraud operations by manipulating browser activity and search-result traffic, and in some variants perform cryptocurrency mining. ZeroAccess has also been described as a malware delivery platform capable of installing credential- and financial-theft malware. Research has additionally noted that its peer-to-peer design could be abused for reflective denial-of-service amplification.
Distribution has been associated with fake antivirus campaigns and socially engineered lures themed as media files, pornography, software updates, and similar deceptive executables. ZeroAccess has been linked to hidden process injection behavior and difficult post-infection remediation, contributing to its reputation as one of the more technically sophisticated commodity malware families of its era. The botnet was the subject of major disruption efforts by Microsoft, Europol, the FBI, and industry partners because of its scale and its substantial financial impact on online advertising ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ZeroAccess / Max++ / Smiscer Crimeware Rootkit sample for Step-by-Step Reverse Engineering ... Malware Type Rootkit ZeroAccess (aka MAX++) Advanced rootkit used in FakeAV installations.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The Pigeon clickbot therefore hooks several functions in a few libraries... Hooking these functions has the effect of a user-mode rootkit.
Distribution : FakeAV- e.g. Antivirus2010 ... used to deliver FakeAntivirus crimeware applications that trick users into paying $70 to remove the “antivirus”.
Part 3: Reverse Engineering the Kernel-Mode Device Driver Process Injection Rootkit
TDL3 was the first malware system to store its configuration files and payload in a hidden encrypted storage area on the target system, instead of relying on the filesystem service provided by the operating system.
the droppers phone home in two different ways during installation; each time specific functionality needs a server address there is usually a backup address if the first cannot be reached.
ZeroAccess rootkit is far from new and exciting but but this is a fresh lot with still active C2 servers.
Communication with the C&C server is encrypted... The initial post always starts with ‘0|’... The second POST request to the C&C server is unencrypted and uses only the previously received hash to request an additional payload.
the latest version of the malware, which is designed for either click fraud or Bitcoin mining
In distributed reflective denial-of-service (DRDoS) attacks, adversaries send requests to public servers (e.g., open recursive DNS resolvers) and spoof the IP address of a victim. These servers, in turn, flood the victim with valid responses and – unknowingly – exhaust its bandwidth.
184 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a major commodity malware family that once attracted substantial technical analysis.
Mentioned as a complex threat that adopted TDL3’s hidden storage approach.
Botnet referenced historically; previously disrupted by law enforcement/industry in 2013, with discussion focused on the identified developer.
An early P2P botnet targeting Windows machines, mentioned as historical context for P2P botnet evolution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.