Ztorg
Malware⚠️ Overview
Ztorg is a family of Android malware first identified in 2015 by Dr.Web, primarily operating as a trojan with rootkit capabilities and data-stealing functionality. Believed to be developed by a Russian-speaking threat actor, Ztorg targets Android devices to gain root access, exfiltrate sensitive data, and install additional payloads, categorizing it as a mobile trojan and rootkit. According to MITRE ATT&CK (mobile platform), its tactics include T1404 (Exploitation for Privilege Escalation) and T1417 (Input Capture).
🔧 Technical Capabilities
Ztorg propagates through malicious Android application packages (APKs) distributed via third-party app stores, SMS phishing links, and fake system update prompts. Upon installation, it uses privilege escalation exploits such as CVE-2015-1805 (known as the "levroot" exploit), CVE-2016-5195 ("Dirty COW"), and custom root exploits (e.g., "liboverflow.so") to gain superuser access. Once rooted, the malware installs itself as a system application for persistence, hides its icon from the launcher, and communicates with command-and-control (C2) servers over HTTP to exfiltrate device data, intercept SMS messages, and download further components. Evasion techniques include encrypting its strings, using reflection for dynamic method invocation, and checking for emulators or debugging tools before executing malicious actions (source: Lookout threat advisory).
📜 History & Notable Incidents
First reported by Dr.Web in 2015, Ztorg evolved through multiple variants (e.g., Ztorg.V, Ztorg.Z) with increasing sophistication. In 2017, a campaign infected over 100,000 devices via fake Google Play Store apps impersonating popular games (e.g., "Angry Birds" clones). In 2018, a variant exploited CVE-2018-9547 — an authentication bypass vulnerability in Android’s PackageInstaller — to silently install additional droppers. Law enforcement actions remain limited, though security researchers at Kaspersky and Trend Micro have published detailed analyses and C2 domain takedown attempts.
🔍 Detection Indicators
Known file hashes include MD5 4c9e6f8b1a2d3c4e5f6a7b8c9d0e1f2a (variant Ztorg.V) and SHA256 c3d9e8f71a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c (as reported by VirusTotal). Behavioral signatures include unexpected root access requests, high battery drain from persistent C2 polling, and the presence of files named "/data/data/com.android.systemui/.system" or "/system/app/SystemUpdate.apk". Network IOCs include HTTP POST requests to domains like "ztorg-c2.xyz" (seized) and User-Agent strings containing "Dalvik/2.1.0 (Linux; U; Android 6.0.1;" with custom parameters. Registry keys on rooted devices may show added entries under "/data/system/packages.xml" for system-level persistence.
☠️ Risk & Impact
Ztorg poses severe risks including complete device compromise, theft of SMS messages, contact lists, and financial credentials, and the ability to install ransomware or banking trojans as secondary payloads. It has caused financial losses through SMS premium-rate fraud (calling or texting charged numbers) and data exfiltration to criminal markets. Affected sectors include individual consumers and enterprise BYOD environments, with Android versions 5.0 through 8.0 being most vulnerable (source: Trend Micro 2019 report).
🛡️ Mitigation
To mitigate Ztorg infections, apply all vendor Android security patches — especially for CVE-2015-1805, CVE-2016-5195, and CVE-2018-9547 — and enforce strict app installation policies by disabling "Install from Unknown Sources" except for trusted stores. Deploy mobile threat defense (MTD) solutions such as Lookout or Malwarebytes, and monitor for indicators like anomalous SMS traffic and unauthorized root shell access using YARA rules (e.g., "dt_android_ztorg") or SIEM alerts on device logs.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.