Zero.T is a malware loader associated with the Enfal malware ecosystem and publicly identified in late 2016. It is notable for combining DLL side-loading with steganographic payload delivery. After establishing persistence on a compromised system, Zero.T retrieves BMP image files from command-and-control infrastructure and extracts hidden malicious modules from the images’ least significant bits, allowing payload delivery to blend in with apparently benign image transfers. This use of steganography is intended to reduce detection by network inspection and security monitoring that focus on file type validity or protocol anomalies rather than deep image-content analysis. Operationally, Zero.T has been documented using DLL side-loading to execute malicious payloads through legitimate executables, a technique that supports defense evasion and execution under the guise of trusted software. Its staged architecture and hidden-module extraction indicate a post-compromise loader role rather than a standalone intrusion set. Zero.T is best understood as a malware component within the broader Enfal ecosystem rather than as a named nation-state group. High-confidence public reporting in the supplied facts does not establish a definitive country of origin, victim-country pattern, or sector-specific targeting for Zero.T itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader from the Enfal ecosystem that uses steganography to retrieve malicious modules hidden in BMP images from C2 infrastructure.
Uses DLL side-loading to load malicious payloads.
Uses DLL side-loading to load malicious payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.