ZeroBot is a remote access trojan (RAT) first documented in November 2022 by the Sekoia TDR team, attributed to a Vietnamese-speaking threat actor tracked as UAC-0173. It is categorized as a stealer with botnet capabilities, primarily targeting cryptocurrency wallets, browser credentials, and system information via Telegram-based command and control.
ZeroBot propagates through phishing emails containing malicious ZIP attachments (e.g., "Windows Update.zip") that drop .NET executables. Its attack vector leverages social engineering lures impersonating Ukraine-related military aid forms to exploit geopolitical interest. The malware uses Telegram Bot API as its C2 channel, receiving commands via polling and exfiltrating stolen data as text messages. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include packing with ConfuserEx, checking for debugger environments, and using XOR-encrypted strings to hinder static analysis.
First spotted in the wild in November 2022, ZeroBot was linked by Sekoia to a campaign targeting Ukrainian defense contractors and European government entities in early 2023. No CVEs are directly exploited; the malware relies on user execution of the dropper. As of mid-2024, no law enforcement actions have been publicly reported, but the threat actor's Telegram channels remain intermittently active.
Known file hashes include SHA-256: 5c2b4a1f8e3d7c9b0a6f1e2d3c4b5a67890123456789abcdef0123456789 (example placeholder; Sekoia report provides actual hashes). Behavioral signatures include outbound HTTPS connections to api.telegram.org using User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Mutex names such as "ZeroBot_Mutex" and registry keys under HKCUSoftwareeroBot have been observed.
The malware primarily exfiltrates cryptocurrency wallet private keys, saved browser passwords, and system metadata, leading to financial losses for targeted cryptocurrency holders. Affected sectors include defense, government, and cryptocurrency exchanges, with victims identified in Ukraine, the European Union, and Southeast Asia.
Recommended defenses include blocking api.telegram.org for non-essential hosts, enabling PowerShell logging, and deploying YARA rules matching the .NET payload structure. Sekoia’s public report provides Sigma rules for detection, and organizations should enforce application whitelisting to prevent execution of unknown executables.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.