Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ZeroT

ZeroT

TLP:CLEAR
Family

AI Analysis

· 3 hours ago

Executive Summary

ZeroT serves as a delivery and persistence vector for TA459, often accompanying PlugX to enable persistent remote access. The trojan quietly installs itself on Windows hosts, provides basic reconnaissance, and facilitates lateral movement by enabling larger payloads such as PlugX to execute. Security teams should monitor for both ZeroT artifacts and subsequent PlugX activity.

Enhanced Description

ZeroT is a Windows‑targeted Trojan attributed to the threat actor group TA459 and frequently appears in the same campaigns as the PlugX remote access trojan. The malware’s primary role is to establish an initial foothold, provide persistence, and facilitate the delivery of additional malicious payloads such as PlugX. Once on a target machine, ZeroT quietly installs itself into memory or the file system, often masking its presence by masquerading under legitimate names or leveraging obfuscation techniques common to the group’s toolkit. After installation, ZeroT typically collects basic system reconnaissance data (hostname, OS version, installed software) and may also harvest stored credentials from web browsers and mail clients. This information is used to plan further lateral movement; in many observed incidents the compromised machine then becomes a staging point for PlugX, which takes over remote control, performs credential dumping, exfiltrates data, or expands the foothold across the network.

Key Capabilities

  • Installs secondary malware (e.g., PlugX)
  • Establishes persistence on Windows systems
  • Collects system info and credentials
  • Enables lateral movement within a network

ATT&CK Techniques

T1059
T1055
T1070
T1117

Recommended Actions

  • Deploy endpoint detection & response to identify unusual processes and unauthorized downloads
  • Block outbound traffic to known PlugX command‑and‑control infrastructure
  • Enable detailed PowerShell logging to spot suspicious script execution
  • Apply least privilege to user accounts and monitor for credential dumping tools
  • Regularly update antivirus signatures with the latest ZeroT indicators

Suggested Tags

trojan
windows
APT
TA459
PlugX
remote-access

Confidence Assessment

The analysis is based solely on brief attribution references; detailed behavioral evidence (CAPEC, malware sample logs, network trace data) is lacking. Consequently confidence in the specific capabilities is moderate but limited, and further artifact collection would strengthen this intelligence.

Description

ZeroT is a Trojan used by TA459, often in conjunction with PlugX. (Citation: Proofpoint TA459 April 2017) (Citation: Proofpoint ZeroT Feb 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.