Malware.View on attack.mitre.org
ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014. ZLib is malware and should not be confused with the legitimate compression library from which its name is derived.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
ZLib has the ability to discover and manipulate Windows services. |
| T1036.005 Match Legitimate Resource Name or Location |
ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules. |
| T1041 Exfiltration Over C2 Channel |
ZLib has sent data and files from a compromised host to its C2 servers. |
| T1059.003 Windows Command Shell |
ZLib has the ability to execute shell commands. |
| T1071.001 Web Protocols |
ZLib communicates over HTTP for C2. |
| T1082 System Information Discovery |
ZLib has the ability to enumerate system information. |
| T1083 File and Directory Discovery |
ZLib has the ability to enumerate files and drives. |
| T1105 Ingress Tool Transfer |
ZLib has the ability to download files. |
| T1113 Screen Capture |
ZLib has the ability to obtain screenshots of the compromised system. |
| T1543.003 Windows Service |
ZLib creates Registry keys to allow itself to run as various services. |
| T1560.002 Archive via Library |
The ZLib backdoor compresses communications using the standard Zlib compression library. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.