ATT&CKSoftwareZeroaccess

Zeroaccess

S0027

Malware.View on attack.mitre.org

About this malware

Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1014
Rootkit

Zeroaccess is a kernel-mode rootkit.

T1564.004
NTFS File Attributes

Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Sophos ZeroAccess Open source
    Wyke, J. (2012, April). ZeroAccess. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.