Frequently Asked Questions

Threat Details: ZLoader Banking Malware Campaign

What is the ZLoader banking malware campaign exploiting Microsoft signature verification?

The ZLoader banking malware campaign is a global cyberattack that exploits a Microsoft signature verification vulnerability (CVE-2013-3900) to deliver malware. Attackers use a legitimate remote monitoring tool (Atera) to install malicious files, add exclusions to Windows Defender, and execute payloads. The campaign is notable for using a Microsoft-signed DLL (appContast.dll) that has been tampered with to load the ZLoader binary, bypassing signature checks and evading detection. As of January 2, 2022, the campaign had claimed 2,170 victims across 111 countries, with most affected in the U.S., Canada, India, Indonesia, and Australia. Note: The exact distribution method for the installer file remains unknown. Source

How does the ZLoader campaign evade detection?

The campaign uses multiple layers of obfuscation and detection-evasion techniques. It wraps malicious payloads in a Microsoft-signed DLL (appContast.dll), which is a modified version of AppResolver.dll. By exploiting CVE-2013-3900, attackers append malicious code to a signed file without invalidating its signature, allowing the malware to bypass security controls that rely on signature verification. Note: This technique highlights the importance of validating file integrity beyond signature checks. Source

What is CVE-2013-3900 and how is it exploited in the ZLoader campaign?

CVE-2013-3900 is a WinVerifyTrust signature validation vulnerability in Windows. It allows attackers to append malicious code to a signed portable executable (PE) file without invalidating the signature. In the ZLoader campaign, attackers modify a Microsoft-signed DLL (appContast.dll) to include malicious code, which is then used to load the ZLoader malware while maintaining a valid signature. Note: This vulnerability demonstrates the risks of relying solely on signature validation for file trust. Source

Platform Capabilities & Features

How does Cymulate help organizations defend against threats like ZLoader?

Cymulate provides an AI-powered cyber defense engineering platform that continuously validates security controls, detects exposures, and automates mitigation. Its Exposure Validation and Continuous Threat Exposure Management (CTEM) modules allow organizations to simulate real-world attacks, including those exploiting signature validation vulnerabilities, and assess their defenses. Cymulate's Immediate Threats Module is updated rapidly to reflect new attacks, enabling quick risk assessment and remediation. Note: Cymulate does not prevent attacks directly but helps organizations validate and improve their defenses. Platform details

What types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios to ensure comprehensive security validation. Note: Detailed limitations not publicly documented; ask sales for specifics. Source

How does Cymulate's Immediate Threats Module work?

The Immediate Threats Module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. This module is especially valuable for evaluating exposure to newly discovered vulnerabilities and attack techniques. Note: The module provides assessment and guidance, not direct prevention. Source

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate is SOC2 Type II certified and holds ISO 27001:2013, ISO 27701, and ISO 27017 certifications. It also has CSA STAR Level 1 certification, demonstrating compliance with the Cloud Controls Matrix (CCM). These certifications cover security, availability, confidentiality, privacy, and cloud service security. Note: Certification scope may not cover all modules; verify with Cymulate for details. Source

How does Cymulate protect customer data?

Cymulate uses 2-Factor Authentication (2FA), Single Sign-On (SSO), and Role-Based Access Controls (RBAC) for user authentication and access management. Data is encrypted both in transit and at rest. The platform follows strict secure development life cycle procedures, including code review and vulnerability scanning, and is overseen by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Note: For specific data residency or privacy requirements, contact Cymulate directly. Source

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment and operates in an agentless mode, requiring no additional hardware or complex configuration. Users can start running simulations almost immediately, with only basic infrastructure and internet connectivity required. The platform features an intuitive dashboard and navigation, and customers have access to email and chat support, as well as educational resources. Note: Implementation time may vary for complex environments. Customer feedback

What do customers say about Cymulate's ease of use?

Customers consistently praise Cymulate for its ease of use and intuitive design. For example, Raphael Ferreira, Cybersecurity Manager, stated: "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Other users highlight its user-friendly portal, actionable insights, and suitability for both technical and non-technical stakeholders. Note: Some advanced features may require additional training. Source

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to each organization's needs. Pricing depends on the package selected, the number of assets covered, and the scenarios and features chosen. For a detailed quote, organizations are encouraged to schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed. Schedule a demo

Use Cases & Business Impact

What business impact can customers expect from using Cymulate?

Organizations using Cymulate report an average 30% increase in threat prevention, a 90% improvement in threat detection, and a 52% reduction in critical exposures. Teams experience a 60% boost in operational efficiency, and threat validation is 40X faster than manual methods. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Results may vary based on organization size and security maturity. Case study

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It provides continuous, automated testing and is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may offer different integrations or workflows. Choose Cymulate for rapid, actionable validation; choose AttackIQ if you require specific integrations not covered by Cymulate. Note: Cymulate's acknowledged limitation is that some advanced integrations may require additional configuration. Comparison details

How does Cymulate compare to Mandiant Security Validation?

Cymulate powers its platform with AI and automation, offers rapid deployments, easy integrations, and an intuitive dashboard. It provides a comprehensive attack library with daily updates and actionable remediation guidance. Mandiant Security Validation may offer deeper incident response or threat intelligence services. Choose Cymulate for automated, continuous validation; choose Mandiant if you need integrated incident response. Note: Cymulate may not cover all incident response scenarios. Comparison details

Technical Documentation & Resources

Where can I find technical documentation and resources about Cymulate?

Cymulate provides a resource hub with industry reports, whitepapers, case studies, and technical guides. Key resources include the Threat Studio data sheet and the Detection Engineering Automation Guide. These materials offer in-depth insights into Cymulate's detection engineering, threat validation, and platform capabilities. Note: Some resources may require registration. Resource hub

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

New Zloader Banking Malware Campaign Exploiting Microsoft Signature Verification

January 5, 2022

The campaign is said to have claimed 2,170 victims across 111 countries as of January 2, 2022, with most of the affected parties located in the U.S., Canada, India, Indonesia, and Australia.
It's also notable for the fact that it wraps itself in layers of obfuscation and other detection-evasion methods to elude discovery and analysis.

The attack flow commences with the installation of a legitimate enterprise remote monitoring software called Atera, using it to upload and download arbitrary files as well as execute malicious scripts.
However, the exact mode of distributing the installer file remains unknown as yet.

One of the files is used to add exclusions to Windows Defender, while a second file proceeds to retrieve and execute next-stage payloads, including a DLL file called "appContast.dll" that, in turn, is used to run the ZLoader binary ("9092.dll").

What stands out here is that appContast.dll is not only signed by Microsoft with a valid signature, but also that the file, originally an app resolver module ("AppResolver.dll"), has been tweaked and injected with a malicious script to load the final-stage malware.

This is made possible by exploiting a known issue tracked as CVE-2013-3900 - a WinVerifyTrust signature validation vulnerability - that allows remote attackers to execute arbitrary code via specially crafted portable executables by appending the malicious code snippet while still maintaining the validity of the file signature.