Zhong Stealer is a Windows information-stealing malware family associated with Chinese-speaking cybercriminal activity targeting customer support workflows in cryptocurrency, fintech, financial services, gaming, gambling, and broader Web3-related organizations. It has been observed in campaigns where attackers pose as customers in chat or ticketing systems, use broken Chinese or request assistance in Chinese, and pressure support personnel to open compressed attachments presented as screenshots or troubleshooting material. In multiple reported intrusions, the malware was delivered inside ZIP archives containing Windows executables, including screensaver-format executables, and some payloads were digitally signed with fraudulently obtained EV code-signing certificates to improve trust and reduce detection.
Once executed, Zhong Stealer performs host reconnaissance, establishes persistence on the infected system, and attempts to hinder defensive visibility by disabling event logging. Reported persistence mechanisms include Registry-based autoruns and scheduled tasks. The malware then harvests sensitive data from browsers, including saved credentials, session-related browser data, authentication material, and browser extension data, with particular attention to browsers such as Microsoft Edge and Brave. Stolen information is exfiltrated to attacker-controlled command-and-control infrastructure, including over non-standard network ports. Some reporting also describes multi-stage behavior in which the malware retrieves additional components from cloud-hosted infrastructure before continuing execution.
Zhong Stealer has been linked to social-engineering campaigns abusing support desks and customer chat channels, including incidents in which malicious attachments disguised as screenshots were used to compromise enterprise personnel. The malware family has also been connected to certificate abuse operations in which stolen code-signing certificates were used to sign Zhong Stealer artifacts. It is widely characterized as a credential and cryptocurrency-focused stealer, and some reporting notes behavioral overlap with remote-access-style post-compromise functionality, but the strongest supported classification is as an infostealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It also overlaps with a malware documented by ANY.RUN in February 2025 as Zhong Stealer... the exploited certificates weaponized to sign Zhong Stealer malware artifacts.
It also overlaps with a malware documented by ANY.RUN in February 2025 as Zhong Stealer... the exploited certificates weaponized to sign Zhong Stealer malware artifacts.
The stolen certificates were used to digitally sign payloads delivering Zhong Stealer, a malware family previously associated with cybercrime groups involved in cryptocurrency theft.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Harvesting Credentials (T1552) to extract saved passwords, browser session data and authentication tokens.
...the threat actor was able to use this function to access initialization codes for orders that were approved but pending delivery for EV Code Signing certificate orders... Possession of an initialization code, combined with an approved order, is sufficient to obtain the resulting certificate... they were able to obtain EV Code Signing certificates across a set of customer accounts and CAs.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware overlapping behaviorally and tactically with Golden Gh0st RAT; fraudulently obtained DigiCert certificates were used to sign its artifacts.
An information-stealing malware campaign referenced as having used valid code-signing certificates obtained during the DigiCert incident.
A stealer malware campaign associated with compromised code-signing certificates referenced in the DigiCert incident.
A RAT/stealer hybrid malware family delivered via digitally signed payloads using stolen EV code-signing certificates. The described attack chain includes phishing lures with fake screenshots, first-stage decoy payloads, and retrieval of additional malware from cloud services such as AWS to help evade endpoint detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.