Zox

S0672

Malware.View on attack.mitre.org

About this malware

Zox is a remote access tool that has been used by Axiom since at least 2008.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1001.002
Steganography

Zox has used the .PNG file format for C2 communications.

T1005
Data from Local System

Zox has the ability to upload files from a targeted system.

T1021.002
SMB/Windows Admin Shares

Zox has the ability to use SMB for communication.

T1027.013
Encrypted/Encoded File

Zox has been encoded with Base64.

T1057
Process Discovery

Zox has the ability to list processes.

T1068
Exploitation for Privilege Escalation

Zox has the ability to leverage local and remote exploits to escalate privileges.

T1083
File and Directory Discovery

Zox can enumerate files on a compromised host.

T1105
Ingress Tool Transfer

Zox can download files to a compromised machine.

T1680
Local Storage Discovery

Zox can enumerate attached drives.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Novetta-Axiom Open source
    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.