Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain. [1]
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1564 | .004 | Hide Artifacts: NTFS File Attributes |
Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes.[2] |
Enterprise | T1014 | Rootkit |
Zeroaccess is a kernel-mode rootkit.[1] |