zwShell — Malware Profile
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.
MITRE ATT&CK techniques (11)
- T1016 System Network Configuration Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1033 System Owner/User Discovery
- T1053.005 Scheduled Task
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1112 Modify Registry
- T1543.003 Windows Service