ZoxRPC is a China-linked Windows intrusion tool associated with long-running espionage activity and reported use by multiple Chinese APT groups. It is also referred to as Zox, with later related variants or evolutions including ZoxPNG and BLACKCOFFEE. Reporting ties the tooling lineage to developers in Jinan, China, and links later variants to activity attributed to APT17, APT41, and Leviathan.
The malware is notable for integrating exploit functionality, including a Chinese-adapted MS08-067 component, and for supporting privilege escalation through local and remote exploits. It also supports SMB-based communications and can upload files from compromised systems, indicating use in post-compromise operations for internal movement and data theft. The tool lineage appears to date back to earlier code developed in the 2000s, with ZoxRPC released in 2008 and subsequently evolved into ZoxPNG around 2013.
Operationally, ZoxRPC fits the profile of a Windows backdoor or remote access capability used in targeted intrusions. Its documented behaviors support use after initial compromise for elevated execution, communication over SMB, and transfer of victim data. The broader ZoxRPC/ZoxPNG/BLACKCOFFEE lineage is significant in analyses of Chinese state-linked malware development and tool sharing across espionage clusters.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Chinese variant of MS08-067 is particularly interesting because it forms part of a hacking tool frequently used by Chinese APT groups called ZoxRPC. | It was then further developed into a new tool called ZoxPNG in 2013. As FireEye noted in their ‘Hide and Seek’ report, ZoxPNG is also known as BLACKCOFFEE.
Blackfox credited [mentor] for his guidance on malware development, particularly for the exploit framework ZoxRPC. ZoxRPC evolved into ZoxPNG (also known as BLACK-COFFEE), a malware which MITRE ATT&CK attributed to APT17 and APT41, and the China-linked group Leviathan...
Blackfox credited [mentor] for his guidance on malware development, particularly for the exploit framework ZoxRPC. ZoxRPC evolved into ZoxPNG (also known as BLACK-COFFEE), a malware which MITRE ATT&CK attributed to APT17 and APT41, and the China-linked group Leviathan...
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese APT-associated hacking tool incorporating a Chinese port of the MS08-067 exploit code. The content describes it as frequently used by Chinese APT groups and as the predecessor to ZoxPNG.
Malware with capability to use local/remote exploits for privilege escalation.
Malware capable of uploading files from targeted systems.
Malware that can use SMB as a communications channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.