Netskope Threat Labs

Zlob

ATP Sandbox Adv. HeuristicsAV

Zlob is a trojan first detected in late 2005 that masqueraded as a required video codec delivered through malicious ActiveX components. Once installed it showed popup warnings that imitated Windows security alerts and tricked users into installing rogue anti-spyware programs, and some variants such as DNSChanger changed system DNS settings to reroute traffic. An FBI operation shut down the malware's source servers in late 2011, and the replacement servers closed in July 2012.

First seen
February 2022
Last seen
October 2026
Alert Name
Dropped:Generic.Zlob.88DA37A6
Dropped:Generic.Zlob.95C66FE5
Gen:Variant.Zlob.1
Generic.Zlob.FF76C548
Script-JS.Downloader.Zlob
Trojan.Downloader.JS.Zlob.A
Trojan.Downloader.Zlob.ABIP
Trojan.HTML.Zlob.AG
Trojan.HTML.Zlob.W
Trojan.JS.Zlob.A