zgRAT
- Malware type
- rat, credential-stealer, dropper
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 14:43:14
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets. Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on.
Reports & references
- difesaesicurezza.com — Cybercrime Rfq Dalla Turchia Veicola Agenttesla E Zgrat (report)
- cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
- fortinet.com — Smokeloader Using Old Vulnerabilities (report)
- kcm.trellix.com — Index (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zgrat (report)
- bazaar.abuse.ch — Zgrat (report)