ZxShell
MITRE ATT&CK: S0412 View on attack.mitre.org
Aliases: Sensocode, ZxShell
- First seen
- 2004-01-01 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:36:02
Context
ZxShell is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites. It has been used since at least 2004.
Detection coverage
- 766 Sigma rules
Malware & tools used
- VNC (attack-pattern)
- System Information Discovery (attack-pattern)
- Proxy (attack-pattern)
- Web Protocols (attack-pattern)
- Non-Standard Port (attack-pattern)
- Credential API Hooking (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Query Registry (attack-pattern)
- Data from Local System (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Process Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- File Deletion (attack-pattern)
- Windows Service (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Windows Command Shell (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Create Process with Token (attack-pattern)
- Video Capture (attack-pattern)
Used by threat actors
- Threat Group-3390 (threat-actor)
- Axiom (threat-actor)
- APT41 (threat-actor)
Reports & references
- secureworks.com — Bronze Keystone (report)
- MITRE ATT&CK — G0001 (report)
- secureworks.com — Bronze Union (report)
- Palo Alto Unit 42 — Iron Taurus (report)
- MITRE ATT&CK — G0096 (report)
- Broadcom/Symantec — Lancefly Merdoor Zxshell Custom Backdoor (report)
- virusbulletin.com — Vb2019 Paper Vine Climbing Over Great Firewall Longterm Attack Against China (report)
- Mandiant — Rt Apt41 Dual Operation (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- blackberry.com — Pdfviewer (report)
- risky.biz — Whatiswinnti (report)
- Mandiant — Rpt Apt41 (report)
- secureworks.com — A Peek Into Bronze Unions Toolbox (report)
- virusbulletin.com — Vb2019 Gupan (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zxshell (report)
- blogs.cisco.com — Opening Zxshell (report)
- lab52.io — Apt27 Rootkit Updates (report)
- meltx0r.github.io — Emissary Panda Apt (report)
- github.com — Zxshell (report)
- mp.weixin.qq.com — K1Ublgqd8Kgsip1Ytyybfw (report)
- MITRE ATT&CK — S0412 (report)