Netskope Threat Labs

ZLoader

ATP Sandbox Adv. Heuristics

ZLoader is a banking trojan and malware loader descended from the Zeus code base that steals credentials and delivers additional payloads such as ransomware. Its campaigns spread through malicious documents, fake applications, and malvertising, and its operators added features such as remote access and evasion updates over years of development. The family's combination of banking theft and loader services made it a mainstay of organized criminal campaigns.

First seen
March 2022
Last seen
October 2026
Zloader
Alert Name
ByteCode-MSIL.Downloader.ZLoader
Document-Excel.Downloader.ZLoader
Document-Excel.Trojan.ZLoader
Document-Office.Downloader.ZLoader
Document-Word.Downloader.ZLoader
Document-Word.Trojan.ZLoader
Script-BAT.Trojan.ZLoader
Script-WScript.Trojan.ZLoader
Win32.Downloader.Zloader
Win32.Downloader.ZLoader