ZeroAccess, also known as Sirefef, ZAccess, Max++, and Smiscer, is a Windows crimeware rootkit and peer-to-peer botnet active from approximately 2009. Early variants established stealth by overwriting a legitimate driver and storing components in a concealed encrypted NTFS volume; some variants also hid data in NTFS Extended Attributes. It was used as a covert platform for installing additional malware, notably fake-antivirus payloads and other criminal software. Later variants moved away from kernel-mode rootkit components and operated in user-mode memory, while retaining peer-to-peer command-and-control and plugin delivery. ZeroAccess injected components into running processes, used hidden storage, encrypted peer communications, and incorporated resilience mechanisms intended to impede removal and disruption. Operators primarily monetized infected systems through advertising click fraud and Bitcoin mining. It infected large numbers of consumer and enterprise Windows systems globally, and was distributed through deceptive executable lures, including purported media, application, and software-update files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ZeroAccess / Max++ / Smiscer Crimeware Rootkit sample for Step-by-Step Reverse Engineering ... Malware Type Rootkit ZeroAccess (aka MAX++) Advanced rootkit used in FakeAV installations.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Rustock, TDSS/TDL-1, and ZeroAccess are described as providing process, file, registry, and network hiding functionality in kernel mode.
Distribution : FakeAV- e.g. Antivirus2010 ... used to deliver FakeAntivirus crimeware applications that trick users into paying $70 to remove the “antivirus”.
Part 3: Reverse Engineering the Kernel-Mode Device Driver Process Injection Rootkit
TDSS/TDL-1: “Reg/File/Process/Network hiding”; ZeroAccess: “Hidden encrypted NTFS volume.”
TDL3 was the first malware system to store its configuration files and payload in a hidden encrypted storage area on the target system, instead of relying on the filesystem service provided by the operating system.
the droppers phone home in two different ways during installation; each time specific functionality needs a server address there is usually a backup address if the first cannot be reached.
ZeroAccess rootkit is far from new and exciting but but this is a fresh lot with still active C2 servers.
Communication with the C&C server is encrypted... The initial post always starts with ‘0|’... The second POST request to the C&C server is unencrypted and uses only the previously received hash to request an additional payload.
the latest version of the malware, which is designed for either click fraud or Bitcoin mining
In distributed reflective denial-of-service (DRDoS) attacks, adversaries send requests to public servers (e.g., open recursive DNS resolvers) and spoof the IP address of a victim. These servers, in turn, flood the victim with valid responses and – unknowingly – exhaust its bandwidth.
184 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a major commodity malware family that once attracted substantial technical analysis.
Mentioned as a complex threat that adopted TDL3’s hidden storage approach.
Botnet referenced historically; previously disrupted by law enforcement/industry in 2013, with discussion focused on the identified developer.
An early P2P botnet targeting Windows machines, mentioned as historical context for P2P botnet evolution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.