Netskope Threat Labs

Sirefef

ATP Sandbox Adv. HeuristicsAV

Sirefef (a.k.a. ZeroAccess) is a rootkit and botnet that establishes deep persistence on infected systems and recruits them into a peer to peer botnet used for click fraud and cryptocurrency mining. Its kernel level rootkit hid the malware from the operating system itself, and its massive botnet generated revenue through fake advertising interactions and mining. A civil action by Microsoft and coordinated sinkholing disrupted it in 2013, and it remains a landmark example of rootkit based botnet design.

First seen
February 2022
Last seen
October 2026
Alert Name
Binary.Trojan.Sirefef
Gen:Variant.Sirefef.1019
Gen:Variant.Sirefef.119
Gen:Variant.Sirefef.121
Gen:Variant.Sirefef.124
Gen:Variant.Sirefef.126
Gen:Variant.Sirefef.127
Gen:Variant.Sirefef.1347
Gen:Variant.Sirefef.1882
Gen:Variant.Sirefef.1892