logo

Murkios bot drops files and controls system remotely

ID: 3ae34391-5a4e-5ba8-b1b0-36f2dedd08a0

STIX ID: report--3ae34391-5a4e-5ba8-b1b0-36f2dedd08a0

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed the Murkios bot — a Windows malware that silently installs components (start.exe, systems.exe, winsys.exe, winsystem.exe), installs legitimate Plink (PuTTY) for SSH tunneling, enables and modifies RDP functionality via RDP Wrapper, bypasses UAC, creates persistent scheduled tasks and local user accounts, captures screenshots, and sends harvested data to a C2 (observed IP 193.238.46.117). The report provides dropped file paths, MD5 hashes, the download URL (murikos.in/soft.exe), and detailed command-line persistence and remote-access techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.