Exposing the Hidden Network: Mapping APT27’s ZXShell Rootkit Infrastructure
APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide.

APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide. One of their notable tools is ZXShell a custom-developed rootkit used for persistent access and covert operations within compromised environments.
This post presents a high-level overview of our recent work in infrastructure mapping of the APT27 ZXShell campaign, highlighting critical Indicators of Compromise (IOCs) and providing detection guidance for security operations teams.
Campaign Overview
The ZXShell rootkit is a powerful remote access tool designed for stealth and persistence. Once deployed, it enables attackers to:
Escalate privileges and bypass security controls
Execute arbitrary commands remotely
Monitor and exfiltrate sensitive data
Establish encrypted communication with command-and-control (C2) servers
ZXShell’s flexibility and modular design allow attackers to tailor its functionality to specific targets, making it particularly dangerous in multi-stage intrusions.
Technical Analysis: Infrastructure Mapping

Through our infrastructure mapping and correlation analysis, we have identified key components of the ZXShell campaign:
Command-and-Control Nodes: Distributed globally to obfuscate origin and evade geolocation-based filtering
Malware Staging Servers: Hosting initial dropper files and secondary payloads
Beacon Traffic Patterns: Using common ports and encrypted communications to blend in with normal network traffic
Lateral Movement Infrastructure: Employing compromised internal servers for deeper infiltration into target environments
Our infrastructure mapping identifies both current active nodes and historically linked infrastructure, giving defenders strategic visibility and context to respond proactively.
Indicators of Compromise (IOCs)
Security teams are advised to implement immediate blocking and detection based on the following known malicious hashes associated with ZXShell:
| IOC Type | Value | Scanner | Detection |
|---|---|---|---|
| SHA256 | 42EAB05C611BF24D86BB6C985CAA2AD7380ED7D98340C7F08DE9361BE14DC244 | AVEngine V2 / V3 | Rootkit-ZXShell |
| SHA256 | 9B7C1E37D5F56CC0B5E5E22CE9805E237A189297E78405B9C392A0953B6E0321 | AVEngine V2 / V3 | Rootkit-ZXShell |
Currently, these IOCs do not have active detections in JTI (ATP Rules), RP Static, or RP Dynamic engines, reinforcing the need for proactive infrastructure-based defense mechanisms.
Defensive Recommendations
To mitigate the risk posed by APT27’s ZXShell operations:
- Integrate these IOCs into your SIEM and endpoint detection tools
- Monitor for beaconing behavior to suspicious external IPs/domains
- Conduct regular asset and vulnerability scans to identify at-risk systems
- Isolate and reimage endpoints where ZXShell artifacts are detected
- Review and monitor network traffic for encrypted outbound connections over non-standard ports
Our Services
Our Infrastructure Threat Mapping Service empowers organizations to stay ahead of nation-state threats through:
- Attribution and actor tracking
- Campaign infrastructure visualization
- Tailored threat intelligence feeds
- Custom detection rules and IOC packages
- Ongoing threat monitoring and early warning alerts
With visibility into both historical and current adversary infrastructure, our clients gain critical insights to detect and neutralize threats before damage occurs.



