Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
ZLoader, also known as Silent Night or Zloader 2, is a modular Windows banking trojan descended from the Zeus codebase.
Profile source: Mallory opens in a new tabZLoader
ZLoader, also known as Silent Night or Zloader 2, is a modular Windows banking trojan descended from the Zeus codebase. Active since approximately 2016–2017, it targets online banking, payment, and other financial services through credential theft, browser web injections, keylogging, screenshot capture, and theft of browser cookies, saved logins, email-account data, cryptocurrency-wallet data, and files. Its modular architecture includes downloader, backdoor, VNC, and web-inject components, enabling operators to retrieve and execute additional payloads and remotely access compromised systems.
ZLoader commonly establishes persistence through user-level autorun configuration, stores encrypted operational data locally, injects into legitimate processes, and uses encrypted command-and-control communications with hardcoded, stored, and DGA-derived fallback infrastructure. It has also been used to impair endpoint protections and deliver post-compromise tooling. Criminal operators evolved ZLoader into a malware-as-a-service platform used both for financial theft and for ransomware delivery, including Ryuk; it has also been observed in intrusion chains associated with Egregor and Conti-linked activity.
Delivery has included malicious spam attachments, invoice-themed phishing, exploit-assisted spam, trojanized installers promoted through malicious advertisements and search-result manipulation, fake remote-work software, and fraudulent websites. Victims have included organizations and individuals worldwide, including businesses, healthcare institutions, schools, and home users. Microsoft and industry partners disrupted portions of ZLoader infrastructure in a coordinated legal and technical operation, though its operators were expected to attempt restoration.
C2 tracking
Derp observations, rolling seven-day window
Samples
1674541b7d559c9823d0f9b1c25fc438c719893bb9c22c12d1ee5790684de5f2 17aff5b190d38fd794cf295c3fef90f8a003d574a9a4848e3a805f8600dcf9f6 46e9efbbef9d0c238a710c3c9753483cfea30643ffd92fe273aec4541e4a5b33 79d8037ca36bc6ec69ffd436d7b340737a5af228a114e50430e098bf6403bb03 7dd4976be9cf5e4bd4735bd454dde4011d9573b4d6baa9913d4859126a760af2 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 771f327f1637897150eaaf1fb3fa25209b372d05e50b5000cdc4bee40f9447e9 b206695fb128857012fe280555a32bd389502a1b47c8974f4b405ab19921ac93 db652dee33439c655221933eb268063d7096a7275d038d65f09fd5ec82100d0d Reported operators
A prior effort included a ZLoader banking malware campaign disguised as job applicant emails.
The threat actors authored and operated the TrickBot malware from late 2016 until March 2022 and have also distributed malware such as BazarLoader, Anchor, Zloader, and Buer Loader.
SilentNight est un cheval de Troie vendu sur des forums russophones souterrains depuis fin 2019. Il est une variante du code malveillante Zloader.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
As announced today, Microsoft took action against the ZLoader trojan... Derived from the Zeus banking trojan first discovered in 2007, ZLoader is a malware family notable for its ability to evolve and change from campaign to campaign... ZLoader has previously been linked to ransomware infections such as Ryuk, DarkSide, and BlackMatter.
The IRS-themed emails contained malicious Microsoft Excel documents that requested victims enable macros to view content, thereby downloading and executing the ZLoader malware on a victim machine. ZLoader is a typical banking malware that steals credentials and other private information from users of targeted financial institutions.
In December 2019, Proofpoint researchers observed email campaigns widely distributing a new version of the ZLoader banking malware, which appears to be under active development.
The campaigns related to Zloader have also been previously discussed so we will be focusing on going over the updates and differences in the more recent campaigns... if not then it will install Gozi or Zloader.
Spain (Defunct) Castilian ZLoader Medium Volume Technology, Manufacturing & Hospitality Campaigns began experimentally in August of 2017 and ended in September of 2017.
Since the Emotet takedown, Proofpoint observed consistent, ongoing activity from The Trick, Dridex, Qbot, IcedID, ZLoader, Ursnif, and many others in our data serving as first-stage malware payloads in attempts to enable further infections, including ransomware attacks.
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Researchers identified a TrickBot variant for Microsoft Windows that replaces its usual HTTP command-and-control channel with a custom DNS tunneling mechanism, allowing the malware to hide outbound tasking in malformed DNS queries and reconstruct inbound data from IPv4 addresses returned in DNS responses. Fortinet said the malware sends XOR-encrypted, hex-encoded command data in chunks designed to resemble legitimate domain labels, with traffic observed via 8.8.8.8 and a command-and-control domain of westurn.in. The transport redesign preserves TrickBot’s modular architecture while making communications harder to detect and block. The malware maintains persistence through Windows Task Scheduler, with tasks configured to run every five minutes, and stores task metadata in NTFS Alternate Data Streams to reduce visibility. Fortinet reported the variant also uses encrypted strings and hash-based runtime API resolution to complicate analysis, while retaining capabilities for module download, rundll32-based execution, PowerShell execution, direct machine-code execution, process hollowing, and process doppelgänging. Researchers measured the DNS tunnel at roughly 30.7 KB/s, indicating the channel is practical for sustained covert command-and-control operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.