Zlob is a Windows trojan/downloader family widely associated with fake codec and rogue media-player installation campaigns in the mid-2000s. The provided content links Zlob to deceptive websites such as ZCodec, PlayerCodec, DVDAccess, and related codec-themed domains that socially engineered users into downloading executable installers under the pretense that a codec or access component was required to view media, especially on pornographic sites. The malware is described as being associated with detections including Trojan-Downloader.Zlob, DNSChanger variants, and FakeAlert/Renos-related activity.
The content indicates that Zlob was distributed through fake codec brands including zCodec/ZCodec and as part of the broader Emcodec ecosystem. After execution, related fake codec trojans copied files into Program Files, modified Windows registry keys, and displayed a fake EULA. The zCodec variant reportedly changed DNS settings, monitored browsing activity, and acted as adware. Some Emcodec variants installed Zlob, which in turn could lead to installation of fake security software such as SpywareQuake, SpyFalcon, and WinFixer; some variants also installed a backdoor.
The content further associates Zlob with DNSChanger activity and notes historical reporting suggesting a possible relationship between operators behind the Mac OSX.RSPlug DNS-changing trojan and the group behind Zlob, although the same source also notes disagreement on whether they were actually the same operators. High-confidence infrastructure references in the content include ZCODEC.COM and other ESTDOMAINS-registered codec-themed distribution domains used in coordinated fake codec campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2006 Rustock ZLOB Clickbot Stration
2006 Rustock ZLOB
Referenced as a Windows trojan potentially linked by some researchers to the group behind RSPlug/DNS-changing activity.
Malware 2006 ZLOB
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.