Skip to content

zgRAT

zgRAT is a Windows malware label used in the wild for payloads delivered through multiple commodity malware chains and social-engineering campaigns.

Profile source: Mallory opens in a new tab

zgRAT

Family profile

zgRAT is a Windows malware label used in the wild for payloads delivered through multiple commodity malware chains and social-engineering campaigns. It has been observed as a second-stage payload delivered by loaders and crypters including SmokeLoader, DOILoader, Rhadamanthys, Cruciferra, StealC, and CastleLoader, and in campaigns using phishing emails, fake browser-update pages, and ClickFix-style lures. Targeting associated with zgRAT delivery has included hospitality and travel organizations, logistics firms, and broader opportunistic victim sets across sectors such as financial services, healthcare, and government.

The term "zgRAT" is used inconsistently across the security ecosystem and is not a stable family designation. Multiple researchers have noted that detections labeled zgRAT may actually refer to distinct PureCoder malware families, especially PureRAT and PureLogs. Because of this naming ambiguity, family-level capability claims should be treated cautiously unless a sample is independently classified. Even so, malware reported under the zgRAT label has repeatedly been associated with credential and browser-data theft, cookie theft, cryptocurrency-wallet theft, and remote-access functionality. Some campaigns have also paired zgRAT with PureHVNC or other remote-control tooling, and some detections tied to zgRAT have involved Discord webhooks for exfiltration.

Observed delivery chains commonly rely on Windows-focused execution methods such as malicious Office exploit chains, DLL sideloading, trojanized update installers, archive-delivered shortcut or executable launchers, and staged PowerShell downloaders. In several 2025-2026 campaigns, hospitality-themed lures such as guest complaints and bed-bug reports were used to deliver zgRAT, including activity linked to the Chinese-speaking threat actor TA4922 via the Cruciferra crypter service. The malware has also appeared in fake Chrome update campaigns on compromised websites and in tax- and logistics-themed intrusion chains. Overall, zgRAT is best understood as a commonly referenced but taxonomically ambiguous Windows malware designation associated with credential theft, data exfiltration, and remote-access operations in commodity cybercrime campaigns.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 7, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DK1

Leading providers

  • team.blue Denmark A/S1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Aggah

This PowerShell script ran Rhadamanthys malware. Rhadamanthys was then observed to download and run zgRAT.

MITRE ATT&CK

zgRAT in ATT&CK

25 distinct techniques

Reporting

Research mentioning zgRAT

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

Jul 21
Scworld

Sophisticated crypter service Cruciferra evades detection with advanced techniques | brief | SC Media

Jul 21
Gurucul Threat Research

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Community Portal | Gurucul

Jul 16
Proofpoint

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.