zgRAT

Malware type
rat, credential-stealer, dropper
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 14:43:14

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets. Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on.

Reports & references

  • difesaesicurezza.com — Cybercrime Rfq Dalla Turchia Veicola Agenttesla E Zgrat (report)
  • cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
  • fortinet.com — Smokeloader Using Old Vulnerabilities (report)
  • kcm.trellix.com — Index (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Zgrat (report)
  • bazaar.abuse.ch — Zgrat (report)

External references