Spearphishing Connects PCs To Russian Botnet
ID: 627f711f-9f6b-5fe9-9016-cc59dada785e
STIX ID: report--627f711f-9f6b-5fe9-9016-cc59dada785e
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes a Zbot/Zeus dropper distributed via spear‑phishing PDFs exploiting Adobe Reader (CVE-2013-0640/CVE-2013-2729). The malware installs a persistent rootkit and kernel-level components, beacons to multiple C2 IPs (using nonstandard ports), downloads additional PE files, and hijacks Windows Mail to spear‑phish the victim's contacts; administrators are advised to monitor outbound connections and employ sandboxing for email attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
