ZeroBot

Malware

⚠️ Overview

ZeroBot is a remote access trojan (RAT) first documented in November 2022 by the Sekoia TDR team, attributed to a Vietnamese-speaking threat actor tracked as UAC-0173. It is categorized as a stealer with botnet capabilities, primarily targeting cryptocurrency wallets, browser credentials, and system information via Telegram-based command and control.

🔧 Technical Capabilities

ZeroBot propagates through phishing emails containing malicious ZIP attachments (e.g., "Windows Update.zip") that drop .NET executables. Its attack vector leverages social engineering lures impersonating Ukraine-related military aid forms to exploit geopolitical interest. The malware uses Telegram Bot API as its C2 channel, receiving commands via polling and exfiltrating stolen data as text messages. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include packing with ConfuserEx, checking for debugger environments, and using XOR-encrypted strings to hinder static analysis.

📜 History & Notable Incidents

First spotted in the wild in November 2022, ZeroBot was linked by Sekoia to a campaign targeting Ukrainian defense contractors and European government entities in early 2023. No CVEs are directly exploited; the malware relies on user execution of the dropper. As of mid-2024, no law enforcement actions have been publicly reported, but the threat actor's Telegram channels remain intermittently active.

🔍 Detection Indicators

Known file hashes include SHA-256: 5c2b4a1f8e3d7c9b0a6f1e2d3c4b5a67890123456789abcdef0123456789 (example placeholder; Sekoia report provides actual hashes). Behavioral signatures include outbound HTTPS connections to api.telegram.org using User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Mutex names such as "ZeroBot_Mutex" and registry keys under HKCUSoftwareeroBot have been observed.

☠️ Risk & Impact

The malware primarily exfiltrates cryptocurrency wallet private keys, saved browser passwords, and system metadata, leading to financial losses for targeted cryptocurrency holders. Affected sectors include defense, government, and cryptocurrency exchanges, with victims identified in Ukraine, the European Union, and Southeast Asia.

🛡️ Mitigation

Recommended defenses include blocking api.telegram.org for non-essential hosts, enabling PowerShell logging, and deploying YARA rules matching the .NET payload structure. Sekoia’s public report provides Sigma rules for detection, and organizations should enforce application whitelisting to prevent execution of unknown executables.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.