Skip to content

Malware

ZXShell

aka Sensocode

According to FireEye, ZXSHELL is a backdoor that can be downloaded from the internet, particularly Chinese hacker websites.

ZXShell, also known as Sensocode, is a Windows malware family operated by APT41, EMISSARY PANDA and others.

Background

FireEye describes ZXSHELL as a backdoor that is freely obtainable online, notably from Chinese hacking forums. Its feature set covers port scanning, keylogging, screen capture, the creation of HTTP or SOCKS proxies, spawning a reverse shell, launching SYN floods, and uploading, removing or executing files. The openly distributed build ships with a graphical interface that operators use to control compromised hosts, and the accompanying documentation is written in Simplified Chinese.


Source: Malpedia (Fraunhofer FKIE).