Malware.View on attack.mitre.org
Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
Zeroaccess is a kernel-mode rootkit. |
| T1564.004 NTFS File Attributes |
Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.