ZAPiXDESK
ZAPIXDESK is a malware/tool used by the threat cluster UAC-0247 in an espionage campaign targeting Ukraine, including municipal authorities, local self-government bodies, clinical hospitals, emergency medical services, and in some cases representatives of Ukraine’s Defense Forces and FPV drone operators. CERT-UA reported that the malware was used specifically to steal data from the WhatsApp messenger application, including WhatsApp accounts/data on compromised systems. It was observed alongside other malware and tooling such as AGINGFLY, SILENTLOOP, and CHROMELEVATOR in attacks that commonly began with phishing emails themed around humanitarian aid, links to malicious archive files, and in some cases fake organization websites or compromised legitimate websites. In the broader intrusion set, attackers also conducted reconnaissance, lateral movement, and covert tunneling inside victim networks. The provided content does not include technical implementation details or specific indicators of compromise unique to ZAPIXDESK itself.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniquesThe attacks typically began with phishing emails posing as discussions about proposals for humanitarian aid. Victims were asked to follow a link that led to the download of a malicious archive file.
Victims were asked to follow a link that led to the download of a malicious archive file.
Execution
1 techniqueBouncyCastle.Cryptography.dll must be in the same directory of the ZAPiXDESK.ps1 file... It may also be necessary to enable set the execution policy to Unrestricted or Bypass in PowerShell to execute the script... run script: .\ZAPiXDESK.ps1
Privilege Escalation
1 techniqueOpen PowerShell on target computer (it will attempt to claim administrative rights).
Credential Access
3 techniquesa separate tool called ZAPIXDESK was used specifically to steal data from the WhatsApp messenger application.
First, it obtains the OfflineDeviceUniqueID... It generates the first decryption key to session.db based on staticKey protect by DPAPI-NG than recovers clientKey from WAL file... With clientKey, it is able to derives encryption key... where all other keys were stored and are recovered from WAL file. DbKeys are used to decrypt the others databases.
First, it obtains the OfflineDeviceUniqueID, indicating the method used (TPM, REGISTRY, etc...), used in keys derivations linked to the machine.
Collection
2 techniquesA script that extracts DBKeys and decrypts all SQLITE3 database files (including db and write-ahead-logfiles ). On completion a ZIP file containing all WhatsApp decrypted LocalState db's... The tool copies the WhatsApp localstate files (where SQLite3 DB files are located) to operate them
... або ж з месенджеру WhatsApp (із застосуванням програмного засобу ZAPIXDESK) ...
Command and Control
1 techniqueAlso downloaded to the infected machine is a malware family dubbed AGINGFLY and a PowerShell script referred to as SILENTLOOP
IOCs tracked for this family
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data theft tool used specifically to steal information from the WhatsApp messenger application.
Data-stealing malware used to extract information from WhatsApp.
A theft tool used to extract data from the WhatsApp messenger.
A malware tool used to steal sensitive information from WhatsApp accounts.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.