ZHtrap
- First seen
- 2021-03-01 00:00:00
- Malware type
- botnet, cryptominer
- Family
- Malware family
- Last IoC activity
- 2026-06-29 01:25:06
- Profile updated
- 2026-07-07 14:31:33
Context
ZHtrap is a botnet malware known for its cryptomining capabilities and exploitation of IoT devices. It incorporates a scanning function to locate new vulnerable targets and embeds a honeypot function to lure attackers, using the IP addresses it collects for further infiltration.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Zhtrap (report)
- blog.netlab.360.com — New Threat Zhtrap Botnet En (report)