ZxxZ

S1013

Malware.View on attack.mitre.org

About this malware

ZxxZ is a trojan written in Visual C++ that has been used by BITTER since at least August 2021, including against Bangladeshi government personnel.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

ZxxZ can collect data from a compromised host.

T1012
Query Registry

ZxxZ can search the registry of a compromised host.

T1027.013
Encrypted/Encoded File

ZxxZ has been encoded to avoid detection from static analysis tools.

T1033
System Owner/User Discovery

ZxxZ can collect the username from a compromised host.

T1036.004
Masquerade Task or Service

ZxxZ has been disguised as a Windows security update service.

T1053.005
Scheduled Task

ZxxZ has used scheduled tasks for persistence and execution.

T1057
Process Discovery

ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`.

T1082
System Information Discovery

ZxxZ has collected the host name and operating system product name from a compromised machine.

T1105
Ingress Tool Transfer

ZxxZ can download and execute additional files.

T1106
Native API

ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`.

T1140
Deobfuscate/Decode Files or Information

ZxxZ has used a XOR key to decrypt strings.

T1204.002
Malicious File

ZxxZ has relied on victims to open a malicious attachment delivered via email.

T1518.001
Security Software Discovery

ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus.

T1566.001
Spearphishing Attachment

ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cisco Talos Bitter Bangladesh May 2022 Open source
    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.