Zegost is a Windows malware family most consistently described as an information stealer, although reporting also shows code and operational overlap with other Chinese-language malware clusters, including Purple Fox and FatalRAT-related tooling. It has been observed in both cybercriminal and espionage-associated activity. Zegost has appeared in staged infection chains using shortcut files and MSI-based loaders, and has also been distributed through trojanized software packages in campaigns targeting Chinese-speaking users.
Documented Zegost functionality includes host fingerprinting, keylogging, webcam-related reconnaissance through COM interfaces, and theft of victim information. Reporting on related samples indicates shellcode-based execution and encrypted payload staging. Multiple analyses also note strong code similarities between Zegost and later malware used in Purple Fox operations, suggesting either code reuse, shared developers, or common operators. In Purple Fox-linked activity, overlapping behaviors included victim profiling, anti-analysis-aware module loading, and integration with broader post-compromise tooling.
Zegost has primarily targeted Windows systems. Historical attribution in open reporting is mixed: it has been associated with Chinese cybercriminal activity and has also been observed in intrusion sets aligned with espionage objectives. Some public sources have conflated Zegost with Gh0st RAT, but available reporting does not support treating them as the same malware family with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In September 2022, a few weeks before we first spotted DragonSpark indicators, a sample of Zegost malware – an info-stealer historically attributed to Chinese cybercriminals, but also observed as part of espionage campaigns – was reported communicating with 104.233.163[.]190.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware historically attributed to Chinese cybercriminals and also seen in espionage campaigns.
Zegost is a previously documented info stealer mentioned because the analyzed FatalRAT sample shared code similarities with it.
Named malware discussed as possibly being conflated with Gh0st RAT, though the content argues it appears to be different malware despite some public reporting equating the two.
Zegost is referenced as a historically related malware family sharing code, configuration strings, shellcode-loading patterns, keylogging, fingerprinting, and certificate overlap with Purple Fox components, suggesting code reuse or common lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.