Zollard is a Linux malware family associated with exploitation of CVE-2012-1823 in PHP-CGI deployments on embedded and Internet of Things devices. It has been observed as a multi-architecture threat with samples compiled for processor families commonly used in routers, modems, and similar appliances, indicating an operational focus on heterogeneous embedded environments. Security tooling has identified related samples under the detection name Linux.Trojan.Zollard.
Zollard is notable both as an active threat and as a recognizable competitor within the Linux IoT botnet ecosystem. Other botnets’ process-killing modules have explicitly searched memory for Zollard signatures in order to remove it from infected systems, placing it alongside established Linux bot and worm families that compete for control of vulnerable devices.
Observed activity tied to Zollard includes exploitation attempts that modify PHP security settings to weaken server-side protections before executing malicious code. Reported behavior includes enabling remote inclusion features and disabling or reducing hardening controls, which is consistent with post-exploitation preparation on vulnerable PHP-CGI targets. The family has been linked to attacks against devices that remain on default or weakly maintained configurations, especially embedded systems that lag in patching and firmware updates.
Based on the available facts, Zollard is best characterized as a Linux-targeting trojan or worm-like malware used in opportunistic compromise of exposed embedded systems through known web-facing vulnerabilities. High-confidence reporting supports its role in exploitation-driven initial access against IoT and embedded Linux devices, but the supplied facts do not establish a fuller capability set such as distributed denial-of-service, credential theft, or persistence with sufficient certainty.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The issue being exploited in those posts is CVE-2012-1823, which has both an existing Cisco IPS signature as well as some for Snort. It turns out this vulnerability is actually quite heavily exploited by many different worms... | We have been able to associate the following md5s with this malware, which is detected by the clamAV signature “Linux.Trojan.Zollard” ... specifically the piece of malware that uses the “User-Agent: Zollard” indicator.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Zollard is identified as a competing malware family whose signatures are scanned for and terminated by the Mirai variant's killer module.
Zollard is mentioned as a competing bot whose processes are terminated by HNS and Mirai killer modules.
Multi-architecture Linux malware targeting Internet-connected embedded/IoT devices by exploiting PHP-CGI vulnerability CVE-2012-1823. The exploit disables or weakens PHP hardening settings, enables arbitrary PHP inclusion, and is used to compromise devices across architectures including PPC, MIPS, MIPSEL, and x86.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.