LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0251: Zebrocy

Zebrocy is a Trojan that has been used by APT28 since at least November 2015. The malware comes in several programming language variants, including C++, Delphi, AutoIt, C#, VB.NET, and Golang. [1][2][3][4]

EnterpriseS0251MalwareObject v3.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Zebrocy matters because ATT&CK describes it as a Windows Trojan used by APT28 since at least November 2015, with multiple language variants. For leaders, the defensive value is not the malware name alone; it is the behavior cluster around discovery, persistence, command execution, collection, command-and-control, and exfiltration. If an organization cannot see registry queries, WMI or command-shell execution, scheduled tasks or logon-script persistence, local staging, and web or mail protocol C2 patterns on Windows endpoints, it may struggle to investigate this family of activity or produce credible incident and audit evidence.

Executive priority

Prioritize Zebrocy as a validation case for Windows endpoint visibility, SOC readiness, and incident response evidence quality. The ATT&CK relationships show behaviors that can support credential access, persistence, data collection, and exfiltration over C2 channels, so the business question is whether security teams can rapidly prove scope: which host executed suspicious commands, what persistence was created, what data may have been staged, and what external communications occurred. This is especially relevant for control investment decisions around EDR, centralized Windows logging, network monitoring, and response playbooks.

Technical view

ATT&CK provides no official detection text for Zebrocy, so defenders should build coverage around the related techniques rather than a single signature. Validate Windows telemetry for Query Registry, WMI, Windows Command Shell, Scheduled Task, Windows logon script persistence, process and system discovery, file and directory enumeration, screen capture, local data staging, file deletion, ingress tool transfer, and C2 over web or mail protocols. Because the malware is described as having C++, Delphi, AutoIt, C#, VB.NET, and Golang variants, detection engineering should avoid relying only on static file indicators and should emphasize behavioral correlations across execution, persistence, discovery, collection, and outbound communications.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows Registry access and modification events, especially persistence-relevant keys
  • WMI activity logs and process ancestry involving WMI execution
  • Scheduled task creation, modification, and execution records
  • Logon script configuration and execution evidence

Detection direction

  • Correlate discovery-heavy activity with subsequent persistence, staging, and outbound C2 rather than alerting on common administrative commands in isolation.
  • Tune for unusual WMI, cmd.exe, scheduled task, and registry activity by user, host role, parent process, and execution context to reduce false positives from normal administration.
  • Confirm whether endpoint tooling records enough command-line, file, registry, and network context to reconstruct an incident timeline after file deletion or tool transfer.
  • Review direct mail protocol use from endpoints; in many environments this is uncommon and may be higher signal, but exceptions must be baselined.
  • Treat packed or variant binaries as a blind spot for static detection and validate memory/behavioral analytics where available.

Mitigation priorities

  • Start with visibility: ensure Windows endpoints, network egress points, and identity-relevant systems produce centralized, retained telemetry for the behaviors listed in the ATT&CK relationships.
  • Harden and monitor persistence paths including scheduled tasks and Windows logon scripts, with change control for legitimate administrative use.
  • Restrict and monitor high-risk execution paths such as WMI and command shell usage where business operations allow.
  • Apply least privilege and administrative separation so discovery and persistence attempts from standard user contexts are easier to detect and contain.
  • Control outbound communications by enforcing proxying, DNS logging, and egress rules for web and mail protocols instead of allowing unrestricted endpoint connections.
Additional notes and limits

This take is based on the supplied ATT&CK malware object, external references, and relationship context. The most decision-useful context is that Zebrocy is a Windows Trojan associated in ATT&CK with APT28 use and a broad set of related techniques spanning discovery, execution, persistence, collection, C2, exfiltration, and stealth. The object does not provide official detection guidance, so recommendations are framed as validation directions derived from related ATT&CK techniques, not as confirmed detections for every Zebrocy variant.

The supplied object lists Windows as the malware platform and does not specify tactics directly. Several related techniques have broader platform listings, but this take does not expand Zebrocy beyond Windows. No active exploitation status, customer exposure, specific indicators of compromise, campaign targeting, or guaranteed detection coverage is provided in the supplied fields. Local baselines, logging configuration, and environment-specific use of administrative tools are required to judge alert fidelity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Zebrocy

Zebrocy is a Trojan that has been used by APT28 since at least November 2015. The malware comes in several programming language variants, including C++, Delphi, AutoIt, C#, VB.NET, and Golang. [1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

31 rows
DomainIDNameRelationship / procedure
EnterpriseT1124System Time Discovery

Zebrocy gathers the current time zone and date information from the system.[5][4]

EnterpriseT1057Process Discovery

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.[2][5][3][6][7]

EnterpriseT1047Windows Management Instrumentation

One variant of Zebrocy uses WMI queries to gather information.[3]

EnterpriseT1049System Network Connections Discovery

Zebrocy uses netstat -aon to gather network connection information.[6]

EnterpriseT1105Ingress Tool Transfer

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.[1][2][6][7]

EnterpriseT1113Screen Capture

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.[2][5][3][6][7][4]

EnterpriseT1120Peripheral Device Discovery

Zebrocy enumerates information about connected storage devices.[2]

EnterpriseT1033System Owner/User Discovery

Zebrocy gets the username from the system.[5][4]

EnterpriseT1056.004Credential API HookingSub-technique

Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method.[8]

EnterpriseT1041Exfiltration Over C2 Channel

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.[7][4]

EnterpriseT1082System Information Discovery

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information. [1][2][5][3][6][7][4]

EnterpriseT1071.003Mail ProtocolsSub-technique

Zebrocy uses SMTP and POP3 for C2.[1][2][5][3][6]

EnterpriseT1071.001Web ProtocolsSub-technique

Zebrocy uses HTTP for C2.[1][2][5][3][6][7]

EnterpriseT1016System Network Configuration Discovery

Zebrocy runs the ipconfig /all command.[6]

EnterpriseT1083File and Directory Discovery

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory.[8][5][6] Zebrocy can obtain the current execution path as well as perform drive enumeration.[7][4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.[5][6][7]

EnterpriseT1027.002Software PackingSub-technique

Zebrocy's Delphi variant was packed with UPX.[3][7]

EnterpriseT1680Local Storage Discovery

Zebrocy collects the serial number for the storage volume C:\.[1][2][5][3][6][7][4]

EnterpriseT1560Archive Collected Data

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. [8][5][4]

EnterpriseT1037.001Logon Script (Windows)Sub-technique

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.[5]

EnterpriseT1059.003Windows Command ShellSub-technique

Zebrocy uses cmd.exe to execute commands on the system.[6][4]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Zebrocy uses SSL and AES ECB for encrypting C2 communications.[5][6][4]

EnterpriseT1074.001Local Data StagingSub-technique

Zebrocy stores all collected information in a single file before exfiltration.[5]

EnterpriseT1012Query Registry

Zebrocy executes the reg query command to obtain information in the Registry.[6]

EnterpriseT1070.004File DeletionSub-technique

Zebrocy has a command to delete files and directories.[5][6][4]

EnterpriseT1132.001Standard EncodingSub-technique

Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.[7]

EnterpriseT1135Network Share Discovery

Zebrocy identifies network drives when they are added to victim systems.[8]

EnterpriseT1140Deobfuscate/Decode Files or Information

Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads.[2][5]

EnterpriseT1119Automated Collection

Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz.[5][6]

EnterpriseT1053.005Scheduled TaskSub-technique

Zebrocy has a command to create a scheduled task for persistence.[4]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.[6]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.1
Created
Modified
Raw hash
82f36f10b4ed3c72...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.1Current bundle82f36f10b4ed…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  2. [2]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  3. [3]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  4. [4]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  5. [5]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  6. [6]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  7. [7]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  8. [8]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  9. [9]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  10. [10]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  11. [11]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  12. [12]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  13. [13]
    CyberScoop APT28 Nov 2018

    Shoorbajee, Z. (2018, November 29). Accenture: Russian hackers using Brexit talks to disguise phishing lures. Retrieved July 16, 2019.

    Open source URL
  14. [14]
    CyberScoop APT28 Nov 2018

    Shoorbajee, Z. (2018, November 29). Accenture: Russian hackers using Brexit talks to disguise phishing lures. Retrieved July 16, 2019.

    Open source URL
  15. [15]
    CyberScoop APT28 Nov 2018

    Shoorbajee, Z. (2018, November 29). Accenture: Russian hackers using Brexit talks to disguise phishing lures. Retrieved July 16, 2019.

    Open source URL
  16. [16]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  17. [17]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  18. [18]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  19. [19]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  20. [20]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  21. [21]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  22. [22]
    Zebrocy

    (Citation: Palo Alto Sofacy 06-2018)(Citation: Unit42 Cannon Nov 2018)

  23. [23]
    Zebrocy

    (Citation: Palo Alto Sofacy 06-2018)(Citation: Unit42 Cannon Nov 2018)

  24. [24]
    Zebrocy

    (Citation: Palo Alto Sofacy 06-2018)(Citation: Unit42 Cannon Nov 2018)

  25. [25]
    Zekapab

    (Citation: CyberScoop APT28 Nov 2018)(Citation: Accenture SNAKEMACKEREL Nov 2018)

  26. [26]
    Zekapab

    (Citation: CyberScoop APT28 Nov 2018)(Citation: Accenture SNAKEMACKEREL Nov 2018)

  27. [27]
    Zekapab

    (Citation: CyberScoop APT28 Nov 2018)(Citation: Accenture SNAKEMACKEREL Nov 2018)

  28. [28]
    mitre-attackS0251
    Open source URL
  29. [29]
    mitre-attackS0251
    Open source URL
  30. [30]
    mitre-attackS0251
    Open source URL
  31. [31]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  32. [32]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  33. [33]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  34. [34]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  35. [35]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  36. [36]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  37. [37]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  38. [38]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  39. [39]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  40. [40]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  41. [41]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  42. [42]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  43. [43]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  44. [44]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  45. [45]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  46. [46]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  47. [47]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  48. [48]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  49. [49]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  50. [50]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  51. [51]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  52. [52]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  53. [53]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  54. [54]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  55. [55]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  56. [56]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  57. [57]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  58. [58]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  59. [59]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  60. [60]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  61. [61]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  62. [62]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  63. [63]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  64. [64]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  65. [65]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  66. [66]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  67. [67]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  68. [68]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  69. [69]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  70. [70]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  71. [71]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  72. [72]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  73. [73]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  74. [74]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  75. [75]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  76. [76]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  77. [77]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  78. [78]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  79. [79]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  80. [80]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  81. [81]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  82. [82]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  83. [83]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  84. [84]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  85. [85]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  86. [86]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  87. [87]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  88. [88]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  89. [89]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  90. [90]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  91. [91]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  92. [92]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  93. [93]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  94. [94]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  95. [95]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  96. [96]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  97. [97]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  98. [98]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  99. [99]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  100. [100]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  101. [101]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  102. [102]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  103. [103]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  104. [104]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  105. [105]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  106. [106]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  107. [107]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  108. [108]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  109. [109]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  110. [110]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  111. [111]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  112. [112]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  113. [113]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  114. [114]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  115. [115]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  116. [116]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  117. [117]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  118. [118]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  119. [119]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  120. [120]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  121. [121]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  122. [122]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  123. [123]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  124. [124]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  125. [125]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  126. [126]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  127. [127]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  128. [128]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  129. [129]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  130. [130]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  131. [131]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  132. [132]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  133. [133]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  134. [134]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  135. [135]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  136. [136]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  137. [137]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  138. [138]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  139. [139]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  140. [140]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  141. [141]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  142. [142]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  143. [143]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  144. [144]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  145. [145]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  146. [146]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  147. [147]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  148. [148]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  149. [149]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  150. [150]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  151. [151]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  152. [152]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  153. [153]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  154. [154]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  155. [155]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  156. [156]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  157. [157]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  158. [158]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  159. [159]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  160. [160]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  161. [161]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  162. [162]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  163. [163]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  164. [164]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  165. [165]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  166. [166]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  167. [167]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  168. [168]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  169. [169]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  170. [170]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  171. [171]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  172. [172]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  173. [173]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  174. [174]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  175. [175]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  176. [176]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  177. [177]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  178. [178]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  179. [179]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  180. [180]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  181. [181]
    Palo Alto Sofacy 06-2018

    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

    Open source URL
  182. [182]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  183. [183]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  184. [184]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  185. [185]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  186. [186]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  187. [187]
    Unit42 Sofacy Dec 2018

    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

    Open source URL
  188. [188]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  189. [189]
    Accenture SNAKEMACKEREL Nov 2018

    Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

    Open source URL
  190. [190]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  191. [191]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  192. [192]
    Unit42 Cannon Nov 2018

    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

    Open source URL
  193. [193]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
  194. [194]
    ESET Zebrocy Nov 2018

    ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

    Open source URL
  195. [195]
    CISA Zebrocy Oct 2020

    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

    Open source URL
  196. [196]
    ESET Zebrocy May 2019

    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.