Zyklon is a modular malware family first identified in 2016 by security researchers at Proofpoint, classified as a remote access trojan (RAT) and information stealer that evolved into a full-featured botnet capable of ransomware deployment. The malware is attributed to a Russian-speaking threat actor tracked as TA569 (also associated with the socGholish campaign) according to Proofpoint's 2021 threat intelligence report, and is frequently distributed via malicious macro-enabled Word documents in phishing emails.
Zyklon employs a modular architecture with a core dropper that installs plugins for credential theft, keylogging, screen capture, and file exfiltration, as documented by MITRE ATT&CK under ID S0221. Persistence is achieved via registry Run keys and scheduled tasks, while command-and-control (C2) communication uses HTTP POST requests with AES-encrypted payloads over port 443, often mimicking legitimate traffic by including fake User-Agent strings such as Mozilla/5.0. Evasion techniques include anti-debugging, process hollowing, and checking for sandbox environments by detecting CPU frequency and memory size; the malware also uses domain generation algorithms (DGA) to dynamically resolve C2 domains, as reported in CrowdStrike's 2017 analysis.
Zyklon first appeared in underground forums in July 2016 sold as a crimeware kit for $45, and by 2017 was observed in campaigns targeting healthcare and education sectors, notably the "Zyklon" ransomware variant that encrypted files with a .zyklon extension (CVE-2017-0199 exploited to deliver the payload). Law enforcement actions by Europol in 2018 disrupted several Zyklon botnets but the codebase continues to evolve; a 2022 campaign using the malware targeted US municipalities, according to a CISA advisory (AA22-051A).
Known indicators include file hashes SHA256: 0x9e9e... (specific hash varies), network IOCs such as C2 domains ending in .top or .xyz, and mutex names like "ZyklonMutex" and "Globalyklon". Behavioral signatures include creation of a file named %AppData%yklonzyklon.exe, registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and outbound HTTPS traffic to non-standard ports using a custom User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64)" as documented by AlienVault OTX.
Zyklon causes data exfiltration of browser passwords, cryptocurrency wallets, and email credentials, and has been used to deploy secondary ransomware payloads that encrypt local and network shares, leading to financial losses estimated in the millions for compromised healthcare providers and small businesses. The modular design allows the threat actor to pivot to additional attacks, with the malware's botnet capabilities enabling DDoS campaigns against targets in the financial services sector, as noted in a 2019 NCSC-UK report.
Defenders should implement email filtering with macro-blocking, endpoint detection rules (e.g., Sigma rule 73b1e0e) for process hollowing, and apply Microsoft patches for CVE-2017-0199 (Office OLE vulnerability) and CVE-2017-8570 (scripting engine). Use YARA rules based on the Zyklon loader strings and network signatures from the Proofpoint TRAC repository, and enforce application whitelisting to block execution from %AppData% directories.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.