Trojan.MSIL.Zapchast.gen
Trojan.MSIL.Zapchast.gen is a spyware-class malware family/detection name referenced in reporting on active exploitation of Dassault Systèmes Delmia Apriso vulnerabilities in 2025. Public reporting cited by CISA-linked coverage states that SANS researcher Johannes Ullrich observed attackers exploiting Delmia Apriso CVE-2025-5086 to download a DLL named fwitxz01.dll, which some antivirus vendors flagged as malicious and which Kaspersky classifies as Trojan.MSIL.Zapchast.gen. The malware is described as supporting cyber-espionage activity, including keylogging, screenshot capture, and collection of active application lists. The reported infection vector in the provided content is delivery via exploitation of the Delmia Apriso deserialization vulnerability CVE-2025-5086; the broader campaign context also includes exploitation of Delmia Apriso CVE-2025-6204 and CVE-2025-6205. The affected environment discussed in the source material is manufacturing operations management infrastructure, where Delmia Apriso is used to control physical manufacturing processes. Organizations mentioned as users of the platform include RTX, Lockheed Martin, L'Oréal, Electrolux, and Spirit AeroSystems. A specific indicator mentioned in the content is the downloaded payload filename fwitxz01.dll. No threat actor attribution beyond unspecified attackers/hackers is provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA in September warned that hackers were exploiting a separate deserialization of an untrusted data vulnerability flaw in Delmia Apriso software tracked as CVE-2025-5086. Dassault published a patch in June. That flaw came to public attention after Sans Institute researcher Johannes Ullrich spotted hackers using it to download fwitxz01.dll, a file flagged as malicious by some antivirus firms. Kaspersky classifies the file as Trojan.MSIL.Zapchast.gen, spyware that includes a key logger and that can take screenshots.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan.MSIL.Zapchast.gen is a Windows trojan/spyware used for cyber espionage, capable of keylogging, screenshot capture, and collecting information about running applications.
Spyware (MSIL/.NET) detected as Trojan.MSIL.Zapchast.gen; includes keylogging and screenshot capture capabilities.
Spyware (MSIL/.NET) detected as Trojan.MSIL.Zapchast.gen; includes keylogging and screenshot capture capabilities.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.