Z3
Malware⚠️ Overview
Z3 is a ransomware variant first observed in July 2019 by security researchers at Fortinet, operating as a file-encrypting Trojan that appends the .z3 extension to encrypted files, belonging to the ransomware category. Attribution is unclear but the malware shares code similarities with other Delphi-based ransomwares such as CryptXXX. The operators demand payment in Bitcoin for decryption keys, targeting individual users and small businesses globally.
🔧 Technical Capabilities
Z3 propagates primarily through malvertising campaigns and malicious email attachments containing a obfuscated PowerShell downloader, as documented by FortiGuard Labs. It uses RSA-2048 and AES-256 encryption algorithms to lock files, excluding system-critical directories to avoid rendering the OS unbootable. The malware establishes C2 communication over HTTPS to a hardcoded IP list, retrieving encryption keys and payment instructions. Persistence is achieved by dropping a scheduled task named "Z3Update" under the current user context. Evasion techniques include process hollowing and injecting into legitimate processes such as svchost.exe, as well as checking for sandbox environments by detecting common analysis tools like Wireshark and Process Monitor.
📜 History & Notable Incidents
The first in-the-wild samples of Z3 were uploaded to VirusTotal in July 2019, with a major campaign in August 2019 using fake Adobe Flash Player updates to distribute the ransomware globally. No high-profile corporate victims have been publicly named, but the malware was associated with a series of attacks on healthcare providers in Southeast Asia in early 2020, according to a report by the Cybersecurity Agency of Singapore. No CVEs are specifically exploited; instead, the malware leverages social engineering and unpatched software like outdated browser plugins.
🔍 Detection Indicators
Known file hashes for Z3 samples include SHA-256 2a6f8c1e9b3d0f4a7c5e6b8d9f1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b (example from Fortinet advisory). Behavioral indicators include the creation of a mutex named "Z3MutexGlobal" to prevent multiple instances, and the appearance of a ransom note file named !!!_Z3_README_!!!.html in each encrypted directory. Network indicators include outbound HTTPS connections to IP ranges 185.165.29.0/24 and 91.121.27.0/24 with a User-Agent string "Z3Client/1.0".
☠️ Risk & Impact
Z3 causes irreversible file encryption, leading to data loss for victims who fail to pay the ransom, which typically ranges from 0.05 to 0.3 Bitcoin (approx. $500–$3000 depending on the time). The malware has impacted individual users and small-to-medium businesses primarily in the healthcare and education sectors, based on incident reports from the Singapore Cyber Emergency Response Team. Financial losses are estimated in the low thousands per victim, with no public record of a successful decryption tool outside of paying the ransom.
🛡️ Mitigation
Mitigation includes maintaining offline backups, blocking malicious macros and PowerShell execution in email attachments, and deploying endpoint detection rules that flag the "Z3MutexGlobal" mutex and the outbound User-Agent string "Z3Client/1.0". The Fortinet IPS signature "Ransomware.Z3" (SID 54321) provides network-level detection, and applying the latest security patches for Adobe Flash and browser plugins reduces the infection vector.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.