Zapata is a provisional threat actor designation derived from a distinctive developer fingerprint embedded in a Windows credential-stealing malware sample. The malware associated with this name is a 32-bit DLL dropper that masquerades as a benign verification component while spoofing Microsoft version metadata and embedding multiple legitimate Microsoft DLLs to facilitate DLL sideloading and search-order hijacking. Embedded version information includes the actor marker "Zapata" and the product name "Mental Management Layer," indicating a deliberate build and branding workflow, although this fingerprint could represent a pseudonym or false flag rather than a firmly attributed operator identity. Activity associated with Zapata shows a focus on stealthy Windows post-compromise malware execution. Observed tradecraft includes anti-analysis and defense-evasion measures such as timing-based debugger detection, breakpoint scanning, XOR-encoded data, and manual PE export-table walking to resolve APIs dynamically rather than relying on conventional imports. The malware proxies legitimate DLL functionality while executing malicious logic in parallel, improving concealment during sideloading operations. The malware has been assessed as a credential-stealing trojan and also performs host and user discovery through registry access and collection of system and foreground-window information. Delivery appears consistent with web-based malware distribution. There is limited but notable indication of possible spreading behavior, suggesting potential lateral movement or propagation capability, though this remains less certain than the credential-theft and sideloading functionality. No high-confidence command-and-control infrastructure, victimology, or state affiliation is established from the available evidence. Zapata should therefore be treated as an emerging, low-confidence actor label tied to a specific malware development fingerprint rather than a fully attributed intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.