zgRAT is a malware designation used for Windows payloads associated with remote access and information theft. The name is inconsistently applied to PureLogs and PureRAT, two distinct .NET malware families developed by PureCoder, and does not reliably identify a single malware type. Detection signatures bearing the zgRAT label can match either family or broadly match .NET Reactor-protected binaries, so their capabilities should not be treated as interchangeable.
Payloads identified as zgRAT have been delivered through phishing emails, compromised websites displaying counterfeit Google Chrome updates, and ClickFix pages that persuade victims to execute PowerShell commands. Delivery chains have involved SmokeLoader, DOILoader, Cruciferra, Rhadamanthys, and StealC. Observed execution chains use encrypted or obfuscated payloads and DLL side-loading through legitimate executables. One Office-based infection chain exploited CVE-2017-0199 and CVE-2017-11882 before delivering the payload through SmokeLoader. Malware identified as zgRAT has also abused Discord webhooks to exfiltrate sensitive information, including credentials, browser cookies, and cryptocurrency-wallet data.
Hospitality and travel organizations are recurring targets. Campaigns have used guest complaints, bed-bug allegations, and Booking.com verification themes, including Italian-language lures targeting hotel personnel. A late-June 2026 campaign delivered zgRAT through Cruciferra using guest-complaint emails. Infrastructure associated with zgRAT has also overlapped with TA558-linked activity, although this does not establish exclusive ownership or operation by that group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
It tricks unsuspecting users into downloading what appears to be an update to their Chrome browser, but is actually a remote access trojan (RAT).
Like many phishing stories, this one starts with a lure urging the recipient to review a purchase order and check for dates related to shipping times to ensure they are correct.
These messages contained URLs masquerading as links to evidence provided by a guest, but led to the download of a zipped LNK file that launched a PowerShell command, which then executed a PowerShell script.
At the very bottom of the source code the bad actors lodged JavaScript code which triggers the malicious download whenever a user clicks on the “Update” button.
These messages contained URLs leading to a download of a JavaScript file hosted on Microsoft Azure. The JavaScript called PowerShell to run a remote PowerShell script.
The DLL is heavily obfuscated. However, it’s still possible to pick out the primary namespace, class, and entry function.
MITRE ATT&CK Mapping ... Defense Evasion Obfuscated Files: Software Packing T1027.002 Donut + .NET Reactor + ZgRAT (three-layer packing)
The file is described as “WinRAR” (legitimate file compression and archiving software). In addition, the original and current file names do not match... “receipt.doc” ... is not a Microsoft Word document. Instead, it is a Rich Text File (RTF).
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
MITRE ATT&CK Mapping Tactic Technique ID Implementation Discovery System Owner/User Discovery T1033 Username, admin status collection
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via a Cruciferra-enabled campaign targeting hotels and travel companies.
Remote access trojan delivered in campaigns using Cruciferra.
A misleading and inconsistently used malware label in this reference, applied ambiguously to both PureLogs and PureRAT rather than a clearly defined single malware family.
A misleading and inconsistently used malware label discussed as causing confusion because it is applied to both PureLogs and PureRAT rather than representing a clearly defined single malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.