ZxxZ

Malware updated 4 months ago (2024-05-04T20:52:46.931Z)
Download STIX
Preview STIX
Zxxz is a malware that can be used by adversaries to target and compromise victim's machines. The trojan is named after a separator used by the payload when sending information to the C2 server. Once installed, Zxxz has remote file execution capability, allowing the attacker to deploy and run other tools from their arsenal to achieve their malicious objective. In current campaigns, Zxxz is downloaded into the public user's account space via a scheduled task while another task runs the trojan. During C2 communication, the trojan sends the victim's computer name, user name, a "ZxxZ" separator, and the Windows version obtained from the registry. Zxxz is a new trojan based on Apost and has been identified by security experts as a significant threat due to its sophisticated capabilities. To prevent falling victim to this malware, users are advised to avoid suspicious downloads, emails, and websites, keep their software up-to-date, and use strong passwords or two-factor authentication.
Description last updated: 2023-06-23T18:03:52.629Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the ZxxZ Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Bitter APT adds Bangladesh to their targets