Skip to content

ZLoader

ZLoader, also known as Silent Night or Zloader 2, is a modular Windows banking trojan descended from the Zeus codebase.

Profile source: Mallory opens in a new tab

ZLoader

Family profile

ZLoader, also known as Silent Night or Zloader 2, is a modular Windows banking trojan descended from the Zeus codebase. Active since approximately 2016–2017, it targets online banking, payment, and other financial services through credential theft, browser web injections, keylogging, screenshot capture, and theft of browser cookies, saved logins, email-account data, cryptocurrency-wallet data, and files. Its modular architecture includes downloader, backdoor, VNC, and web-inject components, enabling operators to retrieve and execute additional payloads and remotely access compromised systems.

ZLoader commonly establishes persistence through user-level autorun configuration, stores encrypted operational data locally, injects into legitimate processes, and uses encrypted command-and-control communications with hardcoded, stored, and DGA-derived fallback infrastructure. It has also been used to impair endpoint protections and deliver post-compromise tooling. Criminal operators evolved ZLoader into a malware-as-a-service platform used both for financial theft and for ransomware delivery, including Ryuk; it has also been observed in intrusion chains associated with Egregor and Conti-linked activity.

Delivery has included malicious spam attachments, invoice-themed phishing, exploit-assisted spam, trojanized installers promoted through malicious advertisements and search-result manipulation, fake remote-work software, and fraudulent websites. Victims have included organizations and individuals worldwide, including businesses, healthcare institutions, schools, and home users. Microsoft and industry partners disrupted portions of ZLoader infrastructure in a coordinated legal and technical operation, though its operators were expected to attempt restoration.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 23, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • CN1

Leading providers

  • IDC, China Telecommunications Corporation1

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
TA547

A prior effort included a ZLoader banking malware campaign disguised as job applicant emails.

WIZARD SPIDER

The threat actors authored and operated the TrickBot malware from late 2016 until March 2022 and have also distributed malware such as BazarLoader, Anchor, Zloader, and Buer Loader.

TA511

SilentNight est un cheval de Troie vendu sur des forums russophones souterrains depuis fin 2019. Il est une variante du code malveillante Zloader.

Water Minyades

Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.

FIN7

As announced today, Microsoft took action against the ZLoader trojan... Derived from the Zeus banking trojan first discovered in 2007, ZLoader is a malware family notable for its ability to evolve and change from campaign to campaign... ZLoader has previously been linked to ransomware infections such as Ryuk, DarkSide, and BlackMatter.

TA574

The IRS-themed emails contained malicious Microsoft Excel documents that requested victims enable macros to view content, thereby downloading and executing the ZLoader malware on a victim machine. ZLoader is a typical banking malware that steals credentials and other private information from users of targeted financial institutions.

Hancitor

In December 2019, Proofpoint researchers observed email campaigns widely distributing a new version of the ZLoader banking malware, which appears to be under active development.

ConfCrew

The campaigns related to Zloader have also been previously discussed so we will be focusing on going over the updates and differences in the more recent campaigns... if not then it will install Gozi or Zloader.

TA544

Spain (Defunct) Castilian ZLoader Medium Volume Technology, Manufacturing & Hospitality Campaigns began experimentally in August of 2017 and ended in September of 2017.

TA571

Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.

Exploited software

Vulnerabilities linked to ZLoader

6 CVEs

MITRE ATT&CK

ZLoader in ATT&CK

113 distinct techniques

Techniques

113 techniques
T1497 Virtualization/Sandbox Evasion T1539 Steal Web Session Cookie T1185 Browser Session Hijacking T1055 Process Injection T1059.005 Visual Basic T1555 Credentials from Password Stores T1113 Screen Capture T1090 Proxy T1057 Process Discovery T1056.001 Keylogging T1553.002 Code Signing T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment T1583.008 Malvertising T1568.002 Domain Generation Algorithms T1562 Impair Defenses T1649 Steal or Forge Authentication Certificates T1071 Application Layer Protocol T1568 Dynamic Resolution T1105 Ingress Tool Transfer T1027.013 Encrypted/Encoded File T1071.001 Web Protocols T1218 System Binary Proxy Execution T1059.003 Windows Command Shell T1218.011 Rundll32 T1132 Data Encoding T1566 Phishing T1059 Command and Scripting Interpreter T1036 Masquerading T1027 Obfuscated Files or Information T1548 Abuse Elevation Control Mechanism T1140 Deobfuscate/Decode Files or Information T1204 User Execution T1583 Acquire Infrastructure T1543 Create or Modify System Process T1482 Domain Trust Discovery T1189 Drive-by Compromise T1204.002 Malicious File T1055.003 Thread Execution Hijacking T1005 Data from Local System T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1059.001 PowerShell T1027.007 Dynamic API Resolution T1106 Native API T1218.007 Msiexec T1027.002 Software Packing T1608.006 SEO Poisoning T1588.001 Malware T1082 System Information Discovery T1135 Network Share Discovery T1056 Input Capture T1070 Indicator Removal T1083 File and Directory Discovery T1573.001 Symmetric Cryptography T1566.002 Spearphishing Link T1219 Remote Access Tools T1556.003 Pluggable Authentication Modules T1055.012 Process Hollowing T1497.001 System Checks T1021.005 VNC T1583.004 Server T1529 System Shutdown/Reboot T1041 Exfiltration Over C2 Channel T1074.001 Local Data Staging T1012 Query Registry T1518.001 Security Software Discovery T1556 Modify Authentication Process T1562.001 Disable or Modify Tools T1036.001 Invalid Code Signature T1547 Boot or Logon Autostart Execution T1583.001 Domains T1548.002 Bypass User Account Control T1489 Service Stop T1036.005 Match Legitimate Resource Name or Location T1584.004 Server T1574.001 DLL T1211 Exploitation for Defense Evasion T1124 System Time Discovery T1070.004 File Deletion T1056.003 Web Portal Capture T1557 Adversary-in-the-Middle T1560.003 Archive via Custom Method T1016 System Network Configuration Discovery T1204.001 Malicious Link T1588.006 Vulnerabilities T1555.003 Credentials from Web Browsers T1573 Encrypted Channel T1490 Inhibit System Recovery T1218.005 Mshta T1587.002 Code Signing Certificates T1090.001 Internal Proxy T1587.003 Digital Certificates T1047 Windows Management Instrumentation T1588.002 Tool T1033 System Owner/User Discovery T1587.001 Malware T1001 Data Obfuscation T1059.007 JavaScript T1008 Fallback Channels T1560 Archive Collected Data T1553.004 Install Root Certificate T1218.010 Regsvr32 T1055.001 Dynamic-link Library Injection T1620 Reflective Code Loading T1622 Debugger Evasion T1584 Compromise Infrastructure T1104 Multi-Stage Channels T1568.001 Fast Flux DNS T1608.001 Upload Malware T1486 Data Encrypted for Impact T1071.004 DNS T1553.005 Mark-of-the-Web Bypass

Reporting

Research mentioning ZLoader

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 23
Cyber Security News

TrickBot Turns Ordinary DNS Traffic Into a Hidden Channel for Malware Commands

Researchers identified a TrickBot variant for Microsoft Windows that replaces its usual HTTP command-and-control channel with a custom DNS tunneling mechanism, allowing the malware to hide outbound tasking in malformed DNS queries and reconstruct inbound data from IPv4 addresses returned in DNS responses. Fortinet said the malware sends XOR-encrypted, hex-encoded command data in chunks designed to resemble legitimate domain labels, with traffic observed via 8.8.8.8 and a command-and-control domain of westurn.in. The transport redesign preserves TrickBot’s modular architecture while making communications harder to detect and block. The malware maintains persistence through Windows Task Scheduler, with tasks configured to run every five minutes, and stores task metadata in NTFS Alternate Data Streams to reduce visibility. Fortinet reported the variant also uses encrypted strings and hash-based runtime API resolution to complicate analysis, while retaining capabilities for module download, rundll32-based execution, PowerShell execution, direct machine-code execution, process hollowing, and process doppelgänging. Researchers measured the DNS tunnel at roughly 30.7 KB/s, indicating the channel is practical for sustained covert command-and-control operations.

Jul 23
Hackread

New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs

Jul 23
Gurucul Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2 | Community Portal | Gurucul

Jul 22
Scworld

TrickBot variant uses DNS tunneling for command and control | brief | SC Media

Jul 22
Fortinet Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.