Cybersecurity report

# ZeroAccess Botnet Resumes Click-Fraud Activity

Sophos (Secureworks Counter Threat Unit research), January 28, 2015. ZeroAccess resurgence: CTU's observation that the peer-to-peer botnet reactivated on 15 January 2015 and resumed distributing click-fraud templates to systems already compromised before the December 2013 disruption.

**Source type:** Cybersecurity report

**Published:** January 28, 2015

**Research grade:** T2

**Used in entries:** 1

## Bibliographic record

**Publisher:** Sophos (Secureworks Counter Threat Unit research)

**Published:** January 28, 2015

**Source type:** Cybersecurity report

**Research grade:** Source grade T2

**Language:** English

**Official record:** Not an official publication

**Address:** [https://www.sophos.com/en-us/blog/zeroaccess-botnet-resumes-click-fraud-activity-after-six-month-break](https://www.sophos.com/en-us/blog/zeroaccess-botnet-resumes-click-fraud-activity-after-six-month-break)

**What it supports:** ZeroAccess resurgence: CTU's observation that the peer-to-peer botnet reactivated on 15 January 2015 and resumed distributing click-fraud templates to systems already compromised before the December 2013 disruption

**Dataset id:** src\_secureworks\_ctu\_zeroaccess\_resumes\_2015

## Research notes

- Authored by the Counter Threat Unit Research Team, originally published by Dell SecureWorks; the research now sits on sophos.com following the Secureworks acquisition.
- The live Sophos page shows no dateline. published\_on (2015-01-28) is taken from the Internet Archive capture of the original Secureworks URL, https://www.secureworks.com/blog/zeroaccess-botnet-resumes-click-fraud-activity-after-six-month-break, which prints 'January 28, 2015'.
- The on-page H1 is 'ZeroAccess Botnet Resumes Click-Fraud Activity'; the phrase 'After Six-Month Break' survives only in the URL slug and is not part of the headline.

How this source is used

Cited 1 time across 1 record type.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Later activity

1 citation

Cited for activity recorded after the takedown.

-
[ZeroAccess click-fraud reactivation](https://takedownindex.org/takedowns/zeroaccess-botnet-disruption)

Same operators, ZeroAccess botnet disruption

Technical evidence

[All sources](https://takedownindex.org/sources)
