Skip to content

Malware

Zacinlo

aka s5mark

Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its other components, presence of man-in-the-browser capabilities that

Zacinlo, also known as s5mark, is a Windows malware family.

Background

Bitdefender summarizes the family's core traits as: a rootkit driver that shields both itself and the malware's other components, man-in-the-browser functionality that intercepts and decrypts SSL traffic, and a cleanup routine that purges rival adware to eliminate competition. It reaches out to its C&C server with details about the host environment, including installed antivirus and other software. Beyond that, it captures screenshots, redirects the browser while potentially altering the DOM tree, and generates traffic inside hidden windows—likely for ad fraud. The malware is highly configurable and leverages Lua scripts internally.


Source: Malpedia (Fraunhofer FKIE).