ZeusAction
Malware⚠️ Overview
ZeusAction is a variant of the Zeus banking trojan family, first documented by Fortinet's FortiGuard Labs in July 2021. It is categorized as a credential stealer and backdoor, primarily targeting online banking credentials and cryptocurrency wallets. The malware is believed to be operated by financially motivated cybercriminal groups, leveraging leaked Zeus source code. Unlike its predecessor, ZeusAction incorporates enhanced evasion techniques and modular payload delivery.
🔧 Technical Capabilities
ZeusAction propagates via malicious email attachments, exploit kits (such as Fallout), and drive-by downloads. Its attack vectors include phishing campaigns with weaponized Office documents and JavaScript downloaders. The malware uses a peer-to-peer (P2P) command-and-control (C2) infrastructure alongside HTTP-based C2 servers, according to a Trend Micro analysis (2021). Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include API unhooking, process hollowing, and anti-debugging checks against sandbox environments. It also implements domain generation algorithms (DGAs) to rotate C2 domains, making takedown difficult. The malware can inject into legitimate processes like explorer.exe and svchost.exe to blend in.
📜 History & Notable Incidents
First detected in mid-2021, ZeusAction was linked to a campaign targeting European banking customers, as reported by Proofpoint in October 2021. A notable incident involved the compromise of a Polish financial institution, leading to unauthorized wire transfers. No specific CVEs are associated with ZeusAction itself; however, it frequently exploits CVE-2017-0144 (EternalBlue) for lateral movement on unpatched Windows systems. Law enforcement actions include a coordinated takedown of Zeus-related domains by Europol in 2022, though ZeusAction variants persisted.
🔍 Detection Indicators
Known file hashes include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Fortinet repository). Behavioral signatures: creation of mutex named ZeusMutexAction and registry keys under HKCUSoftwareMicrosofteusAction. Network IOCs include HTTP POST requests to domains generated by a DGA algorithm (e.g., zeusaction-*.com pattern) and User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) ZeusAction/1.0. Detection rules are available in public YARA signatures from the Malpedia project.
☠️ Risk & Impact
ZeusAction primarily causes financial losses through theft of online banking credentials, cryptocurrency wallet private keys, and two-factor authentication tokens. It has been observed exfiltrating data via encrypted HTTPS channels to C2 servers. The malware predominantly affects the finance and cryptocurrency sectors in Europe and North America, according to a McAfee Advanced Threat Research report (2022).
🛡️ Mitigation
Mitigation includes applying Microsoft security patches (especially MS17-010 for EternalBlue), deploying endpoint detection and response (EDR) solutions with behavioral analysis, and blocking known DGA domains via DNS sinkholing. Organizations should enforce multi-factor authentication and restrict PowerShell execution to prevent dropper activity.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.