zgRAT is a Windows malware label used in the wild for payloads delivered through multiple commodity malware chains and social-engineering campaigns. It has been observed as a second-stage payload delivered by loaders and crypters including SmokeLoader, DOILoader, Rhadamanthys, Cruciferra, StealC, and CastleLoader, and in campaigns using phishing emails, fake browser-update pages, and ClickFix-style lures. Targeting associated with zgRAT delivery has included hospitality and travel organizations, logistics firms, and broader opportunistic victim sets across sectors such as financial services, healthcare, and government.
The term "zgRAT" is used inconsistently across the security ecosystem and is not a stable family designation. Multiple researchers have noted that detections labeled zgRAT may actually refer to distinct PureCoder malware families, especially PureRAT and PureLogs. Because of this naming ambiguity, family-level capability claims should be treated cautiously unless a sample is independently classified. Even so, malware reported under the zgRAT label has repeatedly been associated with credential and browser-data theft, cookie theft, cryptocurrency-wallet theft, and remote-access functionality. Some campaigns have also paired zgRAT with PureHVNC or other remote-control tooling, and some detections tied to zgRAT have involved Discord webhooks for exfiltration.
Observed delivery chains commonly rely on Windows-focused execution methods such as malicious Office exploit chains, DLL sideloading, trojanized update installers, archive-delivered shortcut or executable launchers, and staged PowerShell downloaders. In several 2025-2026 campaigns, hospitality-themed lures such as guest complaints and bed-bug reports were used to deliver zgRAT, including activity linked to the Chinese-speaking threat actor TA4922 via the Cruciferra crypter service. The malware has also appeared in fake Chrome update campaigns on compromised websites and in tax- and logistics-themed intrusion chains. Overall, zgRAT is best understood as a commonly referenced but taxonomically ambiguous Windows malware designation associated with credential theft, data exfiltration, and remote-access operations in commodity cybercrime campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
It tricks unsuspecting users into downloading what appears to be an update to their Chrome browser, but is actually a remote access trojan (RAT).
Like many phishing stories, this one starts with a lure urging the recipient to review a purchase order and check for dates related to shipping times to ensure they are correct.
These messages contained URLs masquerading as links to evidence provided by a guest, but led to the download of a zipped LNK file that launched a PowerShell command, which then executed a PowerShell script.
At the very bottom of the source code the bad actors lodged JavaScript code which triggers the malicious download whenever a user clicks on the “Update” button.
These messages contained URLs leading to a download of a JavaScript file hosted on Microsoft Azure. The JavaScript called PowerShell to run a remote PowerShell script.
The DLL is heavily obfuscated. However, it’s still possible to pick out the primary namespace, class, and entry function.
MITRE ATT&CK Mapping ... Defense Evasion Obfuscated Files: Software Packing T1027.002 Donut + .NET Reactor + ZgRAT (three-layer packing)
The file is described as “WinRAR” (legitimate file compression and archiving software). In addition, the original and current file names do not match... “receipt.doc” ... is not a Microsoft Word document. Instead, it is a Rich Text File (RTF).
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
MITRE ATT&CK Mapping Tactic Technique ID Implementation Discovery System Owner/User Discovery T1033 Username, admin status collection
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via a Cruciferra-enabled campaign targeting hotels and travel companies.
Remote access trojan delivered in campaigns using Cruciferra.
A misleading and inconsistently used malware label in this reference, applied ambiguously to both PureLogs and PureRAT rather than a clearly defined single malware family.
A misleading and inconsistently used malware label discussed as causing confusion because it is applied to both PureLogs and PureRAT rather than representing a clearly defined single malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.