ZLib

S0086

Malware.View on attack.mitre.org

About this malware

ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014. ZLib is malware and should not be confused with the legitimate compression library from which its name is derived.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1007
System Service Discovery

ZLib has the ability to discover and manipulate Windows services.

T1036.005
Match Legitimate Resource Name or Location

ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules.

T1041
Exfiltration Over C2 Channel

ZLib has sent data and files from a compromised host to its C2 servers.

T1059.003
Windows Command Shell

ZLib has the ability to execute shell commands.

T1071.001
Web Protocols

ZLib communicates over HTTP for C2.

T1082
System Information Discovery

ZLib has the ability to enumerate system information.

T1083
File and Directory Discovery

ZLib has the ability to enumerate files and drives.

T1105
Ingress Tool Transfer

ZLib has the ability to download files.

T1113
Screen Capture

ZLib has the ability to obtain screenshots of the compromised system.

T1543.003
Windows Service

ZLib creates Registry keys to allow itself to run as various services.

T1560.002
Archive via Library

The ZLib backdoor compresses communications using the standard Zlib compression library.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.