ZLib is a Windows malware family with remote-access and post-compromise collection capabilities. Observed functionality includes capturing screenshots from compromised systems, executing shell commands, enumerating and manipulating Windows services, and exfiltrating files and collected data to command-and-control infrastructure. It communicates with its operators over HTTP and uses persistence mechanisms involving creation of Windows Registry entries so it can run as services. ZLib also employs defense-evasion through masquerading, including mimicking version-resource metadata associated with legitimate hardware-vendor software components such as Realtek, Nvidia, and Synaptics. The combination of command execution, service interaction, collection, exfiltration, and persistence is consistent with a backdoor used for sustained access on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that copies version metadata from legitimate vendor modules to appear trustworthy.
Backdoor malware capable of obtaining screenshots from compromised systems.
Backdoor malware capable of obtaining screenshots from compromised systems.
Malware that creates Registry keys enabling execution as various Windows services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.