ZLib

MITRE ATT&CK: S0086 View on attack.mitre.org

Aliases: ZLib

First seen
2014-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:18:37

Targeted industries: energy-and-utilities government-and-public-sector

Context

ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014. ZLib is malware and should not be confused with the legitimate compression library from which its name is derived.

Detection coverage

  • 252 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Archive via Library (attack-pattern)
  • Windows Service (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)

Used by threat actors

  • Operation Dust Storm (campaign)

Reports & references

  • s7d2.scene7.com — Op Dust Storm Report (report)
  • MITRE ATT&CK — S0086 (report)

External references