Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 7, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
zgRAT is a Windows malware label used in the wild for payloads delivered through multiple commodity malware chains and social-engineering campaigns.
Profile source: Mallory opens in a new tabzgRAT
zgRAT is a Windows malware label used in the wild for payloads delivered through multiple commodity malware chains and social-engineering campaigns. It has been observed as a second-stage payload delivered by loaders and crypters including SmokeLoader, DOILoader, Rhadamanthys, Cruciferra, StealC, and CastleLoader, and in campaigns using phishing emails, fake browser-update pages, and ClickFix-style lures. Targeting associated with zgRAT delivery has included hospitality and travel organizations, logistics firms, and broader opportunistic victim sets across sectors such as financial services, healthcare, and government.
The term "zgRAT" is used inconsistently across the security ecosystem and is not a stable family designation. Multiple researchers have noted that detections labeled zgRAT may actually refer to distinct PureCoder malware families, especially PureRAT and PureLogs. Because of this naming ambiguity, family-level capability claims should be treated cautiously unless a sample is independently classified. Even so, malware reported under the zgRAT label has repeatedly been associated with credential and browser-data theft, cookie theft, cryptocurrency-wallet theft, and remote-access functionality. Some campaigns have also paired zgRAT with PureHVNC or other remote-control tooling, and some detections tied to zgRAT have involved Discord webhooks for exfiltration.
Observed delivery chains commonly rely on Windows-focused execution methods such as malicious Office exploit chains, DLL sideloading, trojanized update installers, archive-delivered shortcut or executable launchers, and staged PowerShell downloaders. In several 2025-2026 campaigns, hospitality-themed lures such as guest complaints and bed-bug reports were used to deliver zgRAT, including activity linked to the Chinese-speaking threat actor TA4922 via the Cruciferra crypter service. The malware has also appeared in fake Chrome update campaigns on compromised websites and in tax- and logistics-themed intrusion chains. Overall, zgRAT is best understood as a commonly referenced but taxonomically ambiguous Windows malware designation associated with credential theft, data exfiltration, and remote-access operations in commodity cybercrime campaigns.
C2 tracking
Derp observations, rolling seven-day window
Samples
1603f86a42ce554c778991a521beb60369da42e664d2669e7effabf9932bddae 71a0c070e801f8a7b98d016788cf89bc25cb15c3fd44f86779afb5f9ad09095b 8a9a72e8600fc4a05216ad862b61579bc0dd7ea237b970fd3075dd6de8c93bb9 9b97c3d884a7161e86e8a1007c574ace3b72073da3f5b5a4e07987982eb86fc8 aff962450d06364ceed10c537e3a61ad99cab52865f2a67211e70d05dd055c0c Reported operators
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
MITRE ATT&CK
Reporting
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.