#ZetaNile

Malware/Tool

2022-11-22 • AN IN-DEPTH LOOK AT THE NORTH KOREAN THREAT ACTOR, ZINC

ZetaNile is a malware family deployed by ZINC through trojanized open-source applications in social-engineering campaigns. Weaponized PuTTY and KiTTY SSH clients served as entry points for the implant, which collected host and user information, communicated with a hardcoded address over TCP port 22, and deployed a malicious DLL after the victim ran the supplied utility.

Tagged Reports

« Back