logo

ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan

ID: 0b2f8c71-9126-5ef8-a17e-36bac03cae2e

STIX ID: report--0b2f8c71-9126-5ef8-a17e-36bac03cae2e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-01

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

ZLoader (aka Terdot/DELoader) has resurfaced with active development: recent versions add RSA encryption, DGA updates, and a new anti-analysis feature that binds execution to the originally infected host via per-sample Registry and MZ-header checks, making analysis and re-hosting difficult. Separately, threat actors use fraudulent websites hosted on legitimate platforms and black-hat SEO to distribute stealers, and phishing campaigns have been observed delivering Taskun as a loader for Agent Tesla across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.