[Zeroaccess](https://attack.mitre.org/software/S0027) is a kernel-mode [Rootkit](https://attack.mitre.org/techniques/T1014) that attempts to add victims to the ZeroAccess botnet, often for monetary gain. (Citation: Sophos ZeroAccess)
Actors that use this
0 tracked actors
No tracked actor uses this yet
Not linked to any of our tracked MENA actors in actor_software — still browsable via the ATT&CK dictionary above.