Zeroaccess

MITRE ATT&CK: S0027 View on attack.mitre.org

Aliases: Max++, Sirefef, Smiscer, ZAccess

First seen
2011-07-01 00:00:00
Malware type
rootkit, botnet
Family
Malware family
Related IoCs
65 (59 malicious)
Last IoC activity
2026-08-31 19:43:36
Profile updated
2026-07-07 14:44:20

Context

Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.

Recent IoC activity

59 malicious indicators in Maltiverse are attributed to Zeroaccess (S0027). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 23 Sigma rules

Malware & tools used

  • Rootkit (attack-pattern)
  • NTFS File Attributes (attack-pattern)

Detection rules

  • MALPEDIA_Win_Zeroaccess_Auto (yara-rule)

Reports & references

  • virusbulletin.com — Paper Notes Click Fraud American Story (report)
  • researchgate.net — Botnet Protocol Inference In The Presence Of Encrypted Traffic (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Zeroaccess (report)
  • resources.infosecinstitute.com — Zeroaccess Malware Part 3 The Device Driver Process Injection Rootkit (report)
  • blog.malwarebytes.com — Sophos Discovers Zeroaccess Using Rlo (report)
  • resources.infosecinstitute.com — Step By Step Tutorial On Reverse Engineering Malware The Zeroaccessmaxsmiscer Crimeware Rootkit (report)
  • blog.malwarebytes.com — Zeroaccess Anti Debug Uses Debugger (report)
  • malwaretips.com — Zeroaccess Analysis Pdf.606 (report)
  • contagiodump.blogspot.com — Zeroaccess Sirefef Rootkit 5 Fresh (report)
  • resources.infosecinstitute.com — Zeroaccess Malware Part 2 The Kernel Mode Device Driver Stealth Rootkit (report)
  • Broadcom/Symantec — Zeroaccess Indepth 13 En (report)
  • contagiodump.blogspot.com — Zeroaccess Max Smiscer Crimeware (report)
  • resources.infosecinstitute.com — Zeroaccess Malware Part 4 Tracing The Crimeware Origins By Reversing Injected Code (report)
  • MITRE ATT&CK — S0027 (report)
  • sophosnews.files.wordpress.com — Zeroaccess2 (report)

External references