ZeroT is a Windows downloader used since at least summer 2016 in cyberespionage campaigns associated with the China-linked threat actor TA459. It primarily installs the PlugX remote access trojan; some campaigns have also delivered PCRat/Gh0st. Documented targets include military and aerospace organizations in Russia and Belarus, as well as financial analysts covering telecommunications at major financial firms operating in Russia and neighboring countries. Its infrastructure has overlapped with NetTraveler activity.
ZeroT is distributed through spear-phishing emails carrying malicious Microsoft Word documents, Microsoft Compiled HTML Help droppers, and compressed or self-extracting archives. Word-based infection chains have exploited CVE-2012-0158 and CVE-2017-0199. Campaigns have used Russian-language defense-industry and project-themed lures. Execution chains abuse legitimate signed Norman Safeground or McAfee utilities for DLL side-loading, and many samples incorporate a Windows Event Viewer-based User Account Control bypass.
ZeroT decrypts RC4-protected payloads and decompresses them before execution. Its evasion techniques include junk instructions, dummy API calls, altered executable headers, and UPX packing in some associated DLLs. It communicates over HTTP using browser-like headers, with RC4 protecting configuration responses and subsequent beacons. It collects and transmits host information including computer name, local IP address, domain information, system language, and Windows version.
Second-stage payloads can arrive as executable content or be concealed within BMP images using least significant bit steganography. ZeroT extracts the hidden payloads and can create a Windows service to ensure that delivered PlugX malware runs at system startup.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack. | attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan, which in turn downloaded the PlugX Remote Access Trojan (RAT).
In previous campaigns, the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158... Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client. | Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan, which in turn downloaded the PlugX Remote Access Trojan (RAT).
18 distinct techniques documented for this family, organized by ATT&CK tactic.
the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158, or URLs linking to RAR-compressed executables... added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Загрузчик из экосистемы Enfal, использующий стеганографию: скачивает BMP-файлы с C2 и извлекает скрытые в LSB модули вредоносной нагрузки.
Named alongside PlugX in a referenced APT campaign targeting Russia and Belarus. The survey connects that campaign to DLL hijacking involving Norman Safeground antivirus.
Gathers victim IP and domain information and sends it to C2.
Backdoor malware whose shellcode decrypts and decompresses an RC4-encrypted payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.