ZLib
MITRE ATT&CK: S0086 View on attack.mitre.org
Aliases: ZLib
- First seen
- 2014-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:18:37
Targeted industries: energy-and-utilities government-and-public-sector
Context
ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014. ZLib is malware and should not be confused with the legitimate compression library from which its name is derived.
Detection coverage
- 252 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Archive via Library (attack-pattern)
- Windows Service (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Service Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Web Protocols (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- Operation Dust Storm (campaign)
Reports & references
- s7d2.scene7.com — Op Dust Storm Report (report)
- MITRE ATT&CK — S0086 (report)