logo

Spearphishing Connects PCs To Russian Botnet

ID: 627f711f-9f6b-5fe9-9016-cc59dada785e

STIX ID: report--627f711f-9f6b-5fe9-9016-cc59dada785e

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a Zbot/Zeus dropper distributed via spear‑phishing PDFs exploiting Adobe Reader (CVE-2013-0640/CVE-2013-2729). The malware installs a persistent rootkit and kernel-level components, beacons to multiple C2 IPs (using nonstandard ports), downloads additional PE files, and hijacks Windows Mail to spear‑phish the victim's contacts; administrators are advised to monitor outbound connections and employ sandboxing for email attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.