Zeroaccess
MITRE ATT&CK: S0027 View on attack.mitre.org
Aliases: Max++, Sirefef, Smiscer, ZAccess
- First seen
- 2011-07-01 00:00:00
- Malware type
- rootkit, botnet
- Family
- Malware family
- Related IoCs
- 65 (59 malicious)
- Last IoC activity
- 2026-08-31 19:43:36
- Profile updated
- 2026-07-07 14:44:20
Context
Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.
Recent IoC activity
59 malicious indicators in Maltiverse are attributed to Zeroaccess (S0027). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 23 Sigma rules
Malware & tools used
- Rootkit (attack-pattern)
- NTFS File Attributes (attack-pattern)
Detection rules
- MALPEDIA_Win_Zeroaccess_Auto (yara-rule)
Reports & references
- virusbulletin.com — Paper Notes Click Fraud American Story (report)
- researchgate.net — Botnet Protocol Inference In The Presence Of Encrypted Traffic (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zeroaccess (report)
- resources.infosecinstitute.com — Zeroaccess Malware Part 3 The Device Driver Process Injection Rootkit (report)
- blog.malwarebytes.com — Sophos Discovers Zeroaccess Using Rlo (report)
- resources.infosecinstitute.com — Step By Step Tutorial On Reverse Engineering Malware The Zeroaccessmaxsmiscer Crimeware Rootkit (report)
- blog.malwarebytes.com — Zeroaccess Anti Debug Uses Debugger (report)
- malwaretips.com — Zeroaccess Analysis Pdf.606 (report)
- contagiodump.blogspot.com — Zeroaccess Sirefef Rootkit 5 Fresh (report)
- resources.infosecinstitute.com — Zeroaccess Malware Part 2 The Kernel Mode Device Driver Stealth Rootkit (report)
- Broadcom/Symantec — Zeroaccess Indepth 13 En (report)
- contagiodump.blogspot.com — Zeroaccess Max Smiscer Crimeware (report)
- resources.infosecinstitute.com — Zeroaccess Malware Part 4 Tracing The Crimeware Origins By Reversing Injected Code (report)
- MITRE ATT&CK — S0027 (report)
- sophosnews.files.wordpress.com — Zeroaccess2 (report)