ZxShell is a Windows remote access trojan and backdoor used in cyberespionage operations, including activity associated with Axiom (Group 72), APT27 (Emissary Panda), PoisonVine (APT-C-01), and GreenSpot. Its publicly available source code has enabled operators to develop customized variants. Campaigns using ZxShell have employed spearphishing and watering-hole attacks, with targeting that includes government, military, defense, aviation, and research organizations, particularly in China.
ZxShell provides remote desktop access, screenshot capture, keylogging, process enumeration, file deletion, and collection of workstation owner and organization information. It can create local user accounts to support continued access. Customized variants used by GreenSpot add targeted document theft and collection of saved email-account passwords from Internet Explorer, including document selection based on file type, modification time, and military or aviation-related keywords.
ZxShell has been injected into a shared Windows Service Host process and has used the Windows Rundll32 utility to execute DLL components. A rootkit module associated with APT27 conceals network connections and redirects access to malicious files so that applications receive handles to benign files instead. A signed version examined in 2019 functioned on Windows 10. Updates to that module retained its core capabilities while introducing string and API-name obfuscation and restructuring code to reduce detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
另一种是格式攻击文档,利用漏洞CVE-2012-0158来释放并执行可执行文件,同时打开欺骗收件人的“正常”文档文件。... CVE-2012-0158是一个文档格式溢出漏洞... 该组织则使用了MHT格式,这种格式同样可以触发漏洞,而且在当时一段时间内可以躲避多种杀毒软件的查杀。 | 经过安天分析,案例6、7、8中释放的PE文件确定为ZXShell后门家族(分别为3个不同版本),是使用ZXShell源码修改后编译的。
ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.
ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.
ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
First variant of ZxShell was found. Several military and government targets was attacked.
APT27 ... Examples of associated tools: Ghost, ASPXSpy, ZxShell RAT, HyperBro, PlugX RAT...
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
34 distinct techniques documented for this family, organized by ATT&CK tactic.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Classic China-nexus remote access trojan listed as part of APT27's toolset.
Custom backdoor used by Linen Typhoon for command-and-control and persistent access.
Remote access trojan/backdoor used for remote surveillance, credential theft, and persistent access (as characterized in the content).
Backdoor that collects owner and organization information from the target workstation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.