Netskope Threat Labs

Zegost

ATP Sandbox Adv. HeuristicsAV

Zegost is a remote access trojan associated with Chinese speaking actors that gives operators remote desktop control, surveillance, and payload delivery on infected systems. Its campaigns spread through phishing, trojanized applications, and loader chains, and researchers have observed it targeting gaming and technology victims. Detections under this name indicate an active implant that requires full remediation and credential resets.

First seen
January 2022
Last seen
October 2026
Alert Name
Backdoor.Zegost.BC
Backdoor.Zegost.I
DeepScan:Generic.Zegost.1.6D1EF5C2
DeepScan:Generic.Zegost.1.9EFFC69F
DeepScan:Generic.Zegost.3.C4687E47
DOS.Backdoor.Zegost
Dump:Generic.Zegost.270BAF97
Gen:Variant.Zegost.1
Gen:Variant.Zegost.14
Gen:Variant.Zegost.19