zgRAT is a Windows malware label used in the wild for payloads delivered in phishing and malware-delivery chains, but the name is inconsistently applied and does not map cleanly to a single, well-defined family. Security reporting has associated the label with malware distributed through loaders and crypters such as Cruciferra, DOILoader, Rhadamanthys, StealC, and CastleLoader, including campaigns targeting hospitality, travel, and other business sectors with social-engineering lures such as guest complaints, tax themes, and Booking.com impersonation. Observed delivery methods include phishing, ClickFix-style user execution, malicious archives, PowerShell-based staging, and DLL sideloading.
Attribution of capabilities under the zgRAT name is complicated by naming ambiguity. Some analysts map zgRAT to PureLogs, a .NET infostealer associated with theft of credentials, browser cookies, financial data, cryptocurrency-wallet data, VPN credentials, and other sensitive information, with exfiltration sometimes occurring over TLS and in some cases via Discord webhooks. Other analysts map zgRAT to PureRAT, a .NET remote-access trojan associated with Hidden VNC, remote desktop control, webcam and microphone access, keylogging, reverse proxying, code injection, and broader interactive post-compromise control. Because both PureLogs and PureRAT have been labeled zgRAT by different vendors and detections, the term is best treated as an ambiguous umbrella label rather than a deterministic family name.
High-confidence reporting shows that malware called zgRAT has been used in financially motivated intrusion activity and commonly appears alongside other commodity stealers and RATs. It has been observed in campaigns against hospitality and travel organizations, including operations using Booking.com-themed lures and DLL sideloading chains, and in other phishing campaigns where it followed loaders or stealers such as Rhadamanthys. The malware associated with this label is therefore linked at minimum to credential theft, session theft through browser-cookie collection, exfiltration, and in some cases broader remote-access and surveillance functions. Precise family classification should be made cautiously and, where possible, replaced with the more specific family names PureLogs or PureRAT when technical evidence supports that distinction.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams... TA4922 sent victims to fake landing pages hosting ZIP files disguised as tax documents...
These messages contained URLs masquerading as links to evidence provided by a guest, but led to the download of a zipped LNK file that launched a PowerShell command, which then executed a PowerShell script.
These messages contained URLs leading to a download of a JavaScript file hosted on Microsoft Azure. The JavaScript called PowerShell to run a remote PowerShell script.
These messages contained URLs leading to a download of a JavaScript file hosted on Microsoft Azure. The JavaScript called PowerShell to run a remote PowerShell script.
MITRE ATT&CK Mapping ... Defense Evasion Obfuscated Files: Software Packing T1027.002 Donut + .NET Reactor + ZgRAT (three-layer packing)
...fake landing pages hosting ZIP files disguised as tax documents... One wave impersonated the US Social Security Administration...
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
MITRE ATT&CK Mapping Tactic Technique ID Implementation Discovery System Owner/User Discovery T1033 Username, admin status collection
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via a Cruciferra-enabled campaign targeting hotels and travel companies.
Remote access trojan delivered in campaigns using Cruciferra.
A misleading and inconsistently used malware label in this reference, applied ambiguously to both PureLogs and PureRAT rather than a clearly defined single malware family.
A remote-access trojan delivered as a payload by Cruciferra in observed campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.