! ##### ! ! ----- ! ## The!Anatomy!of!the!Attack:!!!Zombie!Zero! ! ### Zombie!Zero! ! - **Zombie!Zero!is!a!suspected!nation;state!sponsored!** **attack!on!targeted!logistics!and!shipping!industries.!** - **Variants!of!this!Advanced!Persistent!Malware!** have!recently!been!seen!in!manufacturing!sectors! as!well.! - **Weaponized!malware!was!delivered!into!customer!** **environments!from!the!Chinese!factory!responsible!** for!selling!a!proprietary!hardware/software!scanner! application!used!in!many!shipping!and!logistic! companies!around!the!world.! - **The!same!hardware!product!with!a!variant!of!this!** **malware!was!sold!and!delivered!to!a!** manufacturing!company!as!well!as!to!seven!other! identified!customers.! - **The!malware!was!embedded!in!a!version!of!** **Windows!XP!installed!on!hardware!at!** manufacturer's!location!in!China.! - **Malware!also!persisted!in!the!Windows!XP!** embedded!version!located!at!the!Chinese!manufacturer's!support!website!hosted!in!China.! ! ! ### Description!of!the!Chinese!hardware/! software!scanner!application!and!the!user! company's!security!environment:! **!** - **Items!being!shipped/transported!are!scanned!as!** **they!are!loaded/offloaded!from!vehicles!such!as!** ships,!trucks,!and!planes.! - **This!scanned!data!(origin,!destination,!contents,!** **value,!to,!from,!etc.)!is!transmitted!to!the!** corporate!ERP!via!an!exterior!wireless!network.!! - **The!customer!deployed!scanners!at!two!major!** **distribution!sites.!!Site!1!had!a!firewall!between!the!** corporate!production!network!and!the!end