logo

APT27__2020__APT27_ZXShell_RootKit_module_updates.pdf

ID: 5c80b9c4-54ef-4117-b118-6d520ba76cf4

STIX ID: report--5c80b9c4-54ef-4117-b118-6d520ba76cf4

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2020-01-14

Last Modified Date: 2020-01-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report compares 2018 and 2019 samples of the ZxShell kernel rootkit used by APT27 (Emissary Panda), describing core capabilities—file redirection and network connection hiding—while noting minor code-level obfuscation to hide hardcoded IOCs and API usage and a signed driver that enables loading on Windows 10.