ZeroT is a Windows downloader associated with China-linked espionage activity, particularly campaigns attributed to TA459 targeting organizations in Russia, Belarus, Central Asia, and neighboring regions. It emerged in 2016 as a first-stage implant used primarily to deliver the PlugX remote access trojan, and less commonly other second-stage malware. Observed targeting has included military, aerospace, and financial-sector entities, especially analysts and organizations connected to regional strategic interests.
ZeroT has been delivered through spearphishing campaigns using malicious Microsoft Office documents, including exploitation of CVE-2012-0158 and CVE-2017-0199, as well as CHM droppers and RAR self-extracting archives. In multiple intrusion chains, the malware relied on DLL sideloading with legitimate signed executables to launch its payload. Many samples also used a UAC bypass via eventvwr.exe to execute malicious components with elevated privileges.
Functionally, ZeroT acts as a downloader and staging implant. It fingerprints infected hosts by collecting system and network information such as computer name, local IP address, domain information, system language, and Windows version, then transmits that data to command-and-control infrastructure over HTTP. Its communications and payload handling have used RC4 encryption, and samples have been observed decrypting and decompressing embedded payloads in memory. Some variants tampered with PE header markers and inserted junk API calls or other obfuscation to hinder analysis.
A notable feature of some ZeroT operations is retrieval of second-stage payloads hidden inside BMP images using least significant bit steganography. After extracting the concealed content, ZeroT can deploy additional malware, most commonly PlugX. It has also been used to establish persistence for delivered payloads by creating a Windows service so the follow-on implant survives reboot.
ZeroT is best characterized as a modular espionage downloader within a broader Chinese intrusion ecosystem that overlaps operationally with PlugX and NetTraveler activity. Its tradecraft combines targeted phishing, DLL sideloading, privilege escalation, encrypted HTTP beaconing, host reconnaissance, and staged payload delivery to support long-term intelligence collection against selected regional targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack. | attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan, which in turn downloaded the PlugX Remote Access Trojan (RAT).
In previous campaigns, the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158... Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client. | Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan, which in turn downloaded the PlugX Remote Access Trojan (RAT).
26 distinct techniques documented for this family, organized by ATT&CK tactic.
the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158, or URLs linking to RAR-compressed executables... added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.
uses PowerShell to download yet another script: power.ps1. This is a PowerShell script that downloads and runs the ZeroT payload cgi.exe.
the HTA’s VBScript changes the window size and location and then uses PowerShell to download yet another script
Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client. These documents were built with MNKit
The encrypted ZeroT payload, named Mctl.mui, is decoded in memory revealing a similarly tampered PE header
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
This executable is obfuscated... dummy API calls inserted in between real instructions... the PE header of ZeroT has been tampered with, specifically the “MZ” and “PE” constants
Usually the DLL is not packed, but we have observed instances compressed by UPX
Analysis of the F.bmp image revealed that it is indeed using Least Significant Bit (LSB) Steganography... embeds data in an image without significantly affecting its appearance.
Defense Evasion. ...Работают сразу две техники: Steganography (T1027.003) для обфускации пейлоада и Embedded Payloads (T1027.009) для сокрытия кода внутри медиафайла.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The payload is actually an HTML Application (HTA) file, not an RTF document.
The encrypted ZeroT payload, named Mctl.mui, is decoded in memory revealing a similarly tampered PE header
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
ZeroT still expects an RC4-encrypted response using a static key ... All posts are encrypted
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Загрузчик из экосистемы Enfal, использующий стеганографию: скачивает BMP-файлы с C2 и извлекает скрытые в LSB модули вредоносной нагрузки.
Gathers victim IP and domain information and sends it to C2.
Backdoor malware whose shellcode decrypts and decompresses an RC4-encrypted payload.
Backdoor that encrypts C2 traffic with RC4.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.