The Zemot dropper is a part of the Upatre malware dowloader that has been detected by security researchers to take advantage of multiple distribution points that include both safe websites, as well as the Asprox/Kuluoz spam botnet.
Microsoft observed the activity of TrojanDownloader: Win32/Upatre.B in late 2013 and it appears to be preferred by cybercriminals for distributing two malware strains (PWS: Win32/Zbot.gen AP and PWS: Win32/Zbot.CF).
In May 2014, the company decided to rename Upatre.B to Zemot in order to distinguish between the two threats that are similar, but with some specificities that differentiate them, enough to mark them as a new malware.
Zemot is part of a network with a complex structure that includes various types of malware. Researchers say the dropper is delivered to the victim's computer via the Magnitude and Nuclear Pack exploit kits, or it may be distributed via the Kuluoz botnet spam sender.
Once Zemot invades a system, it begins to inject click-fraud malware. However, Microsoft says that recently, other types of threats (Rovnix, Viknok, and Tesch) have also been distributed, which can be used to download new malware or steal sensitive information.
It is a complex chain attack that can rely on various intrusion methods until the malware reaches the computer and infects it.
In its analysis, Microsoft points out that Zemot resorts to various techniques to ensure that the module download is successful on all Windows platforms.
It also stores all downloaded files with unique file names which helps not only to avoid detection, but also to increase the number of infections of the same machine.
More details about Zemot can be found here.

