ZAPIXDESK is a malware/tool used by the threat cluster UAC-0247 in an espionage campaign targeting Ukraine, including municipal authorities, local self-government bodies, clinical hospitals, emergency medical services, and in some cases representatives of Ukraine’s Defense Forces and FPV drone operators. CERT-UA reported that the malware was used specifically to steal data from the WhatsApp messenger application, including WhatsApp accounts/data on compromised systems. It was observed alongside other malware and tooling such as AGINGFLY, SILENTLOOP, and CHROMELEVATOR in attacks that commonly began with phishing emails themed around humanitarian aid, links to malicious archive files, and in some cases fake organization websites or compromised legitimate websites. In the broader intrusion set, attackers also conducted reconnaissance, lateral movement, and covert tunneling inside victim networks. The provided content does not include technical implementation details or specific indicators of compromise unique to ZAPIXDESK itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
a separate tool called ZAPIXDESK was used specifically to steal data from the WhatsApp messenger application.
First, it obtains the OfflineDeviceUniqueID... It generates the first decryption key to session.db based on staticKey protect by DPAPI-NG than recovers clientKey from WAL file... With clientKey, it is able to derives encryption key... where all other keys were stored and are recovered from WAL file. DbKeys are used to decrypt the others databases.
A script that extracts DBKeys and decrypts all SQLITE3 database files (including db and write-ahead-logfiles ). On completion a ZIP file containing all WhatsApp decrypted LocalState db's... The tool copies the WhatsApp localstate files (where SQLite3 DB files are located) to operate them
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data theft tool used specifically to steal information from the WhatsApp messenger application.
Data-stealing malware used to extract information from WhatsApp.
A theft tool used to extract data from the WhatsApp messenger.
A malware tool used to steal sensitive information from WhatsApp accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.