Zebrocy (AutoIT)

First seen
2015-06-01 00:00:00
Malware type
backdoor, spyware, trojan
Family
Malware family
Profile updated
2026-07-07 12:43:08

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ru country_code:ua country_code:us country_code:de

Context

Zebrocy is a malware family closely associated with APT28, used for espionage purposes. It is known for its backdoor capabilities allowing attackers to exfiltrate information from targeted systems. The malware typically targets government and public sector entities in various countries including Russia, Ukraine, the United States, and Germany.

Reports & references

  • Kaspersky — 83930 (report)
  • secureworks.com — Iron Twilight (report)
  • ESET — Sednit Update Analysis Zebrocy (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Zebrocy Au3 (report)

External references