logo

Chinese Backdoor Zegost Delivered Via Hacking Team

ID: c0c7a462-07b9-5a44-b5ff-c97b496f9e80

STIX ID: report--c0c7a462-07b9-5a44-b5ff-c97b496f9e80

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabZ observed a drive-by campaign delivering the Zegost backdoor via the Hacking Team Adobe Flash exploit (CVE-2015-5119) from compromised Chinese websites and URL shorteners; the report details the infection chain, payload iterations (with MD5s), persistence mechanisms (DLL hijack, registry run key and service), and Command-and-Control indicators (domain, IP, port).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.