Malware
zwShell
S0350 · Windows
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.
ATT&CK S0350
Malware family
Sigma rules0
YARA rules0
Live IOCs0
▤
Techniques Used
11ATT&CK techniques this malware is documented performing. Each links to its detections - Sigma, vendor SIEM rules, and analytics - so you catch the behaviour even when the binary changes.
⚊
Live Indicators
Indicators are defanged for safe handling. Newest first.
Aliases
zwShell
External lookups - second-class, for what we don’t hold ourselves