Alpha Cyber

Exposing the Hidden Network: Mapping APT27’s ZXShell Rootkit Infrastructure

APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide.

Alpha Cyber Research2 min readupdated 1 Apr 2026
APT-27 ZXShell Rootkit

APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide. One of their notable tools is ZXShell a custom-developed rootkit used for persistent access and covert operations within compromised environments.

This post presents a high-level overview of our recent work in infrastructure mapping of the APT27 ZXShell campaign, highlighting critical Indicators of Compromise (IOCs) and providing detection guidance for security operations teams.

Campaign Overview

The ZXShell rootkit is a powerful remote access tool designed for stealth and persistence. Once deployed, it enables attackers to:

Escalate privileges and bypass security controls
Execute arbitrary commands remotely
Monitor and exfiltrate sensitive data
Establish encrypted communication with command-and-control (C2) servers

ZXShell’s flexibility and modular design allow attackers to tailor its functionality to specific targets, making it particularly dangerous in multi-stage intrusions.

Technical Analysis: Infrastructure Mapping

APT-27 ZXShell Rootkit Graph

Through our infrastructure mapping and correlation analysis, we have identified key components of the ZXShell campaign:

Command-and-Control Nodes: Distributed globally to obfuscate origin and evade geolocation-based filtering
Malware Staging Servers: Hosting initial dropper files and secondary payloads
Beacon Traffic Patterns: Using common ports and encrypted communications to blend in with normal network traffic
Lateral Movement Infrastructure: Employing compromised internal servers for deeper infiltration into target environments

Our infrastructure mapping identifies both current active nodes and historically linked infrastructure, giving defenders strategic visibility and context to respond proactively.

Indicators of Compromise (IOCs)

Security teams are advised to implement immediate blocking and detection based on the following known malicious hashes associated with ZXShell:

IOC TypeValueScannerDetection
SHA25642EAB05C611BF24D86BB6C985CAA2AD7380ED7D98340C7F08DE9361BE14DC244AVEngine V2 / V3Rootkit-ZXShell
SHA2569B7C1E37D5F56CC0B5E5E22CE9805E237A189297E78405B9C392A0953B6E0321AVEngine V2 / V3Rootkit-ZXShell

Currently, these IOCs do not have active detections in JTI (ATP Rules), RP Static, or RP Dynamic engines, reinforcing the need for proactive infrastructure-based defense mechanisms.

Defensive Recommendations

To mitigate the risk posed by APT27’s ZXShell operations:

  • Integrate these IOCs into your SIEM and endpoint detection tools
  • Monitor for beaconing behavior to suspicious external IPs/domains
  • Conduct regular asset and vulnerability scans to identify at-risk systems
  • Isolate and reimage endpoints where ZXShell artifacts are detected
  • Review and monitor network traffic for encrypted outbound connections over non-standard ports

Our Services

Our Infrastructure Threat Mapping Service empowers organizations to stay ahead of nation-state threats through:

  • Attribution and actor tracking
  • Campaign infrastructure visualization
  • Tailored threat intelligence feeds
  • Custom detection rules and IOC packages
  • Ongoing threat monitoring and early warning alerts

With visibility into both historical and current adversary infrastructure, our clients gain critical insights to detect and neutralize threats before damage occurs.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]