Executive Summary
ZeroT serves as a delivery and persistence vector for TA459, often accompanying PlugX to enable persistent remote access. The trojan quietly installs itself on Windows hosts, provides basic reconnaissance, and facilitates lateral movement by enabling larger payloads such as PlugX to execute. Security teams should monitor for both ZeroT artifacts and subsequent PlugX activity.
Enhanced Description
ZeroT is a Windows‑targeted Trojan attributed to the threat actor group TA459 and frequently appears in the same campaigns as the PlugX remote access trojan. The malware’s primary role is to establish an initial foothold, provide persistence, and facilitate the delivery of additional malicious payloads such as PlugX. Once on a target machine, ZeroT quietly installs itself into memory or the file system, often masking its presence by masquerading under legitimate names or leveraging obfuscation techniques common to the group’s toolkit. After installation, ZeroT typically collects basic system reconnaissance data (hostname, OS version, installed software) and may also harvest stored credentials from web browsers and mail clients. This information is used to plan further lateral movement; in many observed incidents the compromised machine then becomes a staging point for PlugX, which takes over remote control, performs credential dumping, exfiltrates data, or expands the foothold across the network.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based solely on brief attribution references; detailed behavioral evidence (CAPEC, malware sample logs, network trace data) is lacking. Consequently confidence in the specific capabilities is moderate but limited, and further artifact collection would strengthen this intelligence.
ZeroT is a Trojan used by TA459, often in conjunction with PlugX. (Citation: Proofpoint TA459 April 2017) (Citation: Proofpoint ZeroT Feb 2017)