ZeroT

S0230

Malware.View on attack.mitre.org

About this malware

ZeroT is a Trojan used by TA459, often in conjunction with PlugX.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1001.002
Steganography

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1016
System Network Configuration Discovery

ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server.

T1027.002
Software Packing

Some ZeroT DLL files have been packed with UPX.

T1027.013
Encrypted/Encoded File

ZeroT has encrypted its payload with RC4.

T1027.016
Junk Code Insertion

ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions.

T1071.001
Web Protocols

ZeroT has used HTTP for C2.

T1082
System Information Discovery

ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server.

T1105
Ingress Tool Transfer

ZeroT can download additional payloads onto the victim.

T1140
Deobfuscate/Decode Files or Information

ZeroT shellcode decrypts and decompresses its RC4-encrypted payload.

T1543.003
Windows Service

ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system.

T1548.002
Bypass User Account Control

Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file.

T1573.001
Symmetric Cryptography

ZeroT has used RC4 to encrypt C2 traffic.

T1574.001
DLL

ZeroT has used DLL side-loading to load malicious payloads.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Proofpoint TA459 April 2017 Open source
    Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.
  2. Proofpoint ZeroT Feb 2017 Open source
    Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.