Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareExploits 1 CVE

Trojan.MSIL.Zapchast.gen

Trojan.MSIL.Zapchast.gen is a spyware-class malware family/detection name referenced in reporting on active exploitation of Dassault Systèmes Delmia Apriso vulnerabilities in 2025. Public reporting cited by CISA-linked coverage states that SANS researcher Johannes Ullrich observed attackers exploiting Delmia Apriso CVE-2025-5086 to download a DLL named fwitxz01.dll, which some antivirus vendors flagged as malicious and which Kaspersky classifies as Trojan.MSIL.Zapchast.gen. The malware is described as supporting cyber-espionage activity, including keylogging, screenshot capture, and collection of active application lists. The reported infection vector in the provided content is delivery via exploitation of the Delmia Apriso deserialization vulnerability CVE-2025-5086; the broader campaign context also includes exploitation of Delmia Apriso CVE-2025-6204 and CVE-2025-6205. The affected environment discussed in the source material is manufacturing operations management infrastructure, where Delmia Apriso is used to control physical manufacturing processes. Organizations mentioned as users of the platform include RTX, Lockheed Martin, L'Oréal, Electrolux, and Spirit AeroSystems. A specific indicator mentioned in the content is the downloaded payload filename fwitxz01.dll. No threat actor attribution beyond unspecified attackers/hackers is provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-5086Remote Code Execution in Dassault Systèmes DELMIA Apriso via Deserialization of Untrusted DataExploited in the wild

CISA in September warned that hackers were exploiting a separate deserialization of an untrusted data vulnerability flaw in Delmia Apriso software tracked as CVE-2025-5086. Dassault published a patch in June. That flaw came to public attention after Sans Institute researcher Johannes Ullrich spotted hackers using it to download fwitxz01.dll, a file flagged as malicious by some antivirus firms. Kaspersky classifies the file as Trojan.MSIL.Zapchast.gen, spyware that includes a key logger and that can take screenshots.

via bank info securitybankinfosecurity.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.