Skip to content

Malware

Zebrocy

aka Zekapab

According to brandefense, Zebrocy is malware that falls into the Trojan category, which the threat actor group APT28/Sofacy has used since 2015.

Zebrocy, also known as Zekapab, is a Windows malware family operated by APT28.

Background

Per brandefense, Zebrocy is a Trojan-class malware that the APT28/Sofacy group has employed since 2015. It is built from three core parts—a Backdoor, a Downloader, and a Dropper. The Downloader and Dropper handle reconnaissance and pulling the main payload onto target systems, while the Backdoor manages persistence, espionage, and data exfiltration.

Rather than being a recent threat, Zebrocy has appeared over the years in numerous languages, among them Delphi, C#, Visual C++, VB.net, and Golang. This reflects how sophisticated threat actors periodically rework the tools in their arsenals using different languages and technologies.


Source: Malpedia (Fraunhofer FKIE).