Executive Summary
zwShell is a long‑standing Delphi‑based RAT used in the Night Dragon supply‑chain attack against critical infrastructure. It provides remote control, data exfiltration, and additional payload delivery, posing significant risk to Windows systems. Security teams should treat any unidentified outbound traffic from known zwShell binaries as high‑severity indicator of compromise.
Enhanced Description
zwShell is a remote access trojan (RAT) developed in Delphi for Windows platforms that has been active since the spring of 2010. The tool was first publicly identified within the Night Dragon campaign, a high-profile supply‑chain attack carried out by state-sponsored actors targeting government and infrastructure organizations worldwide. In this campaign, zwShell was leveraged to remotely control infected hosts, exfiltrate data, and execute additional payloads. Operationally, zwShell demonstrates typical RAT capabilities: it establishes encrypted command‑and‑control channels, accepts a variety of remote commands including file manipulation, screen capture, process enumeration, and keystroke logging, and can download auxiliary malware or scripts. The Delphi codebase is compiled with obfuscation techniques that hinder static analysis, while dynamic behaviors such as persistence via registry modifications and DLL injection have been documented by multiple security labs.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information provided is derived from publicly available security reports describing zwShell’s use in the Night Dragon campaign. While core capabilities are well‑documented, details on version variants, encryption schemes, and full C2 infrastructure remain limited, creating a moderate confidence level with notable gaps for future analysis.
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.(Citation: McAfee Night Dragon)