Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware zwShell

zwShell

TLP:CLEAR
Family

AI Analysis

· 7 hours ago

Executive Summary

zwShell is a long‑standing Delphi‑based RAT used in the Night Dragon supply‑chain attack against critical infrastructure. It provides remote control, data exfiltration, and additional payload delivery, posing significant risk to Windows systems. Security teams should treat any unidentified outbound traffic from known zwShell binaries as high‑severity indicator of compromise.

Enhanced Description

zwShell is a remote access trojan (RAT) developed in Delphi for Windows platforms that has been active since the spring of 2010. The tool was first publicly identified within the Night Dragon campaign, a high-profile supply‑chain attack carried out by state-sponsored actors targeting government and infrastructure organizations worldwide. In this campaign, zwShell was leveraged to remotely control infected hosts, exfiltrate data, and execute additional payloads. Operationally, zwShell demonstrates typical RAT capabilities: it establishes encrypted command‑and‑control channels, accepts a variety of remote commands including file manipulation, screen capture, process enumeration, and keystroke logging, and can download auxiliary malware or scripts. The Delphi codebase is compiled with obfuscation techniques that hinder static analysis, while dynamic behaviors such as persistence via registry modifications and DLL injection have been documented by multiple security labs.

Key Capabilities

  • Establish encrypted command-and-control channel
  • Remote desktop capture and screen sharing
  • File system navigation and manipulation (upload/download/delete)
  • Process enumeration and termination
  • Keystroke logging
  • Persistence via registry modifications and startup folder entry
  • DLL injection into trusted processes
  • Download and execute additional malware scripts

ATT&CK Techniques

T1059.001
T1071.001
T1027
T1105
T1112
T1053
T1106

Recommended Actions

  • Deploy advanced endpoint detection and response solutions capable of detecting Delphi‑based RATs.
  • Block outbound traffic from known zwShell DLL or executable hashes to external IPs on non‑standard ports.
  • Monitor for anomalous PowerShell/command shell activity, especially connections to suspicious C2 domains.
  • "Sign off" unused Windows services that show no legitimate business need and re-scan for registry persistence keys associated with RATs.
  • Educate users about phishing vectors that could deliver initial drops of zwShell.

Suggested Tags

Malware
RAT
Delphi
Night Dragon
Windows
Supply‑Chain Attack
Remote Access Tool

Confidence Assessment

The information provided is derived from publicly available security reports describing zwShell’s use in the Night Dragon campaign. While core capabilities are well‑documented, details on version variants, encryption schemes, and full C2 infrastructure remain limited, creating a moderate confidence level with notable gaps for future analysis.

Description

zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.(Citation: McAfee Night Dragon)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.