APT27__2020__APT27_ZXShell_RootKit_module_updates.pdf
ID: 5c80b9c4-54ef-4117-b118-6d520ba76cf4
STIX ID: report--5c80b9c4-54ef-4117-b118-6d520ba76cf4
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2020-01-14
Last Modified Date: 2020-01-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report compares 2018 and 2019 samples of the ZxShell kernel rootkit used by APT27 (Emissary Panda), describing core capabilities—file redirection and network connection hiding—while noting minor code-level obfuscation to hide hardcoded IOCs and API usage and a signed driver that enables loading on Windows 10.
