ZxShell

MITRE
Tipo Malware:
Other
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[ZxShell](https://attack.mitre.org/software/S0412) is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites. It has been used since at least 2004.(Citation: FireEye APT41 Aug 2019)(Citation: Talos ZxShell Oct 2014)

Tecniche Associate (34)
ID ATT&CK Tattiche
T1005 Data from Local System -
T1007 System Service Discovery -
T1012 Query Registry -
T1021.001 Remote Desktop Protocol -
T1021.005 VNC -
T1033 System Owner/User Discovery -
T1046 Network Service Discovery -
T1055.001 Dynamic-link Library Injection -
T1056.001 Keylogging -
T1056.004 Credential API Hooking -
T1057 Process Discovery -
T1059.003 Windows Command Shell -
T1070.001 Clear Windows Event Logs -
T1070.004 File Deletion -
T1071.001 Web Protocols -
Alias (105)
Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode Sensocode
Metadata
ID: 571
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00