ZxxZ is a Windows trojan associated with Bitter, a South Asian espionage threat actor also tracked as APT-C-08 and T-APT-17. It was used in a campaign active from 2021 that targeted Bangladeshi government entities, including high-ranking officers in the Rapid Action Battalion. The malware is a 32-bit Windows executable compiled in Visual C++ and masquerades as a Windows security update service.
ZxxZ has been delivered through spearphishing emails carrying malicious RTF and Microsoft Excel attachments. The weaponized documents exploited known Microsoft Office vulnerabilities including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802 to execute shellcode and install the trojan after the victim opened the attachment. This delivery pattern aligns with Bitter’s long-running use of phishing for intelligence collection against government and other strategic sectors.
Functionally, ZxxZ supports remote file execution, enabling operators to download and execute additional content on infected systems. It can collect basic host information including the current username, gather data from the compromised host, query the Windows Registry, and check for the presence of security software such as Windows Defender and Kaspersky antivirus. It has also used scheduled tasks for persistence and execution. Reported API usage includes functions such as Process32First, Process32Next, and ShellExecuteA, consistent with host discovery and process interaction. Overall, ZxxZ appears to be a lightweight espionage-oriented trojan used for foothold establishment, host reconnaissance, defense-aware operation, and follow-on payload execution on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence. | The latest campaign, targeting an elite entity of the Bangladesh government, involves sending spear-phishing emails ... to deploy a new trojan dubbed "ZxxZ." ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence. | The latest campaign, targeting an elite entity of the Bangladesh government, involves sending spear-phishing emails ... to deploy a new trojan dubbed "ZxxZ." ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence. | The latest campaign, targeting an elite entity of the Bangladesh government, involves sending spear-phishing emails ... to deploy a new trojan dubbed "ZxxZ." ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The latest campaign, targeting an elite entity of the Bangladesh government, involves sending spear-phishing emails ... to deploy a new trojan dubbed "ZxxZ." ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
"ADVSTORESHELL is capable of starting a process using CreateProcess"; "build_downer has the ability to use the WinExec API"; "Aria-body has the ability to launch files using ShellExecute"
the missives are designed to lure the recipients into opening a weaponized RTF document or a Microsoft Excel spreadsheet that exploits previously known flaws in the software to deploy a new trojan dubbed "ZxxZ."
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can collect the username from a compromised host.
A Windows trojan used in spear-phishing attacks against Bangladeshi government targets. It masquerades as a Windows Security update service, communicates with a C2 server, and enables remote code execution so the attacker can install additional tools and conduct follow-on activity.
A Bitter APT-associated Windows trojan/downloader delivered via weaponized Office documents exploiting Equation Editor vulnerabilities. It collects basic host info, communicates with a C2 over HTTP(S), downloads a remote PE payload (embedded after a 'ZxxZ' separator), writes it under %LOCALAPPDATA%\Debug\<program name>.exe, and executes it (ShellExecuteA). It also checks for AV processes (Windows Defender, Kaspersky) and masquerades as a Windows Security update service.
Backdoor that uses scheduled tasks for both persistence and execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.