Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Zeroaccess

Zeroaccess

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

ZeroAccess is a kernel‑mode rootkit that establishes covert persistence on compromised Windows systems and attempts to connect victims to its botnet for profit‑driven activities. By exploiting kernel structures it conceals malicious payloads and can disrupt or disable security software, posing significant operational risk. The malware’s primary objectives are stealthy data exfiltration, participation in DDoS operations, and potentially broader command distribution within the broader ZeroAccess botnet ecosystem.

Enhanced Description

ZeroAccess is a sophisticated kernel‑mode rootkit that stealthily infiltrates Windows systems and installs its driver to hijack system calls and conceal malicious activity from standard security tools. By modifying kernel structures, it can hide files, processes, registry keys, and network connections, thereby enabling persistent operation across reboots without triggering typical detection mechanisms. Once the module is loaded, ZeroAccess attempts to join the larger ZeroAccess botnet for economic exploitation, such as distributing spam, carrying out distributed denial‑of‑service (DDoS) campaigns, or facilitating data exfiltration. The malware typically communicates with command and control (C2) servers over multiple protocols, embedding traffic in standard port usage to mask its presence further. The malicious code also injects into legitimate processes, escalates privileges, and can bypass security products by manipulating hook functions and stealthily terminating antivirus routines. This combination of kernel‑level manipulation, persistence, and botnet integration makes ZeroAccess a high‑impact threat for both enterprise networks and individual users.

Key Capabilities

  • Kernel‑mode driver installation for persistence
  • Stealthy process, file, registry hiding via rootkit techniques
  • Privilege escalation through kernel manipulation
  • Process injection into legitimate Windows processes
  • Network evasion using standard ports and tunneling
  • Command & Control communication with multiple protocols
  • Possible support for DDoS or spam distribution

Description

Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain. (Citation: Sophos ZeroAccess)

Details

Type
Malware
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.