Threat Spotlight: Group 72, Opening the ZxShell
ID: de4a4a3c-da51-402e-8904-e20c101120b4
STIX ID: report--de4a4a3c-da51-402e-8904-e20c101120b4
Threat Score
78/100
Uploaded: 2026-08-21
Published Date: 2014-10-29
Last Modified Date: 2014-10-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Threat Spotlight analyzes ZxShell, a sophisticated Windows RAT used by Group 72 in Operation SMN, detailing its modules, persistence, C2 infrastructure, keylogging and other remote control capabilities, distribution methods, and indicators, as well as defensive coverage and potential impact on high-value targets across multiple industries.
