Last seven days
- First activity
- Jul 28, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
zgRAT is a Windows malware label used in the wild for payloads delivered in phishing and malware-delivery chains, but the name is inconsistently applied and does not map cleanly to a single, well-defined family.
Profile source: Mallory opens in a new tabzgRAT
zgRAT is a Windows malware label used in the wild for payloads delivered in phishing and malware-delivery chains, but the name is inconsistently applied and does not map cleanly to a single, well-defined family. Security reporting has associated the label with malware distributed through loaders and crypters such as Cruciferra, DOILoader, Rhadamanthys, StealC, and CastleLoader, including campaigns targeting hospitality, travel, and other business sectors with social-engineering lures such as guest complaints, tax themes, and Booking.com impersonation. Observed delivery methods include phishing, ClickFix-style user execution, malicious archives, PowerShell-based staging, and DLL sideloading.
Attribution of capabilities under the zgRAT name is complicated by naming ambiguity. Some analysts map zgRAT to PureLogs, a .NET infostealer associated with theft of credentials, browser cookies, financial data, cryptocurrency-wallet data, VPN credentials, and other sensitive information, with exfiltration sometimes occurring over TLS and in some cases via Discord webhooks. Other analysts map zgRAT to PureRAT, a .NET remote-access trojan associated with Hidden VNC, remote desktop control, webcam and microphone access, keylogging, reverse proxying, code injection, and broader interactive post-compromise control. Because both PureLogs and PureRAT have been labeled zgRAT by different vendors and detections, the term is best treated as an ambiguous umbrella label rather than a deterministic family name.
High-confidence reporting shows that malware called zgRAT has been used in financially motivated intrusion activity and commonly appears alongside other commodity stealers and RATs. It has been observed in campaigns against hospitality and travel organizations, including operations using Booking.com-themed lures and DLL sideloading chains, and in other phishing campaigns where it followed loaders or stealers such as Rhadamanthys. The malware associated with this label is therefore linked at minimum to credential theft, session theft through browser-cookie collection, exfiltration, and in some cases broader remote-access and surveillance functions. Precise family classification should be made cautiously and, where possible, replaced with the more specific family names PureLogs or PureRAT when technical evidence supports that distinction.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.
MITRE ATT&CK
Reporting
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.