ZHtrap

First seen
2021-03-01 00:00:00
Malware type
botnet, cryptominer
Family
Malware family
Last IoC activity
2026-06-29 01:25:06
Profile updated
2026-07-07 14:31:33

Context

ZHtrap is a botnet malware known for its cryptomining capabilities and exploitation of IoT devices. It incorporates a scanning function to locate new vulnerable targets and embeds a honeypot function to lure attackers, using the IP addresses it collects for further infiltration.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Zhtrap (report)
  • blog.netlab.360.com — New Threat Zhtrap Botnet En (report)

External references