ZeroT

Description

(Proofpoint) Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.

Names

Name
ZeroT

Category

Malware

Type

  • Downloader

Information

Mitre Attack

Malpedia

Other Information

Uuid

5cf6ff0f-654a-4a92-8ea7-35f4ebbc0068

Last Card Change

2020-04-23