Naikon

G0019

Threat group.View on attack.mitre.org

About this group

Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020). Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).

While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

Naikon uses commands such as netsh interface show to discover network interface settings.

T1018
Remote System Discovery

Naikon has used a netbios scanner for remote machine identification.

T1036.004
Masquerade Task or Service

Naikon renamed a malicious service taskmgr to appear to be a legitimate version of Task Manager.

T1036.005
Match Legitimate Resource Name or Location

Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables.

T1046
Network Service Discovery

Naikon has used the LadonGo scanner to scan target networks.

T1047
Windows Management Instrumentation

Naikon has used WMIC.exe for lateral movement.

T1053.005
Scheduled Task

Naikon has used schtasks.exe for lateral movement in compromised networks.

T1078.002
Domain Accounts

Naikon has used administrator credentials for lateral movement in compromised networks.

T1137.006
Add-ins

Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.

T1204.002
Malicious File

Naikon has convinced victims to open malicious attachments to execute malware.

T1518.001
Security Software Discovery

Naikon uses commands such as netsh advfirewall firewall to discover local firewall settings.

T1547.001
Registry Run Keys / Startup Folder

Naikon has modified a victim's Windows Run registry to establish persistence.

T1566.001
Spearphishing Attachment

Naikon has used malicious e-mail attachments to deliver malware.

T1574.001
DLL

Naikon has used DLL side-loading to load malicious DLL's into legitimate executables.

Software15

Campaigns0

None recorded.

References3

  1. Baumgartner Golovkin Naikon 2015 Open source
    Baumgartner, K., Golovkin, M.. (2015, May 14). The Naikon APT. Retrieved January 14, 2015.
  2. Baumgartner Naikon 2015 Open source
    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.
  3. CameraShy Open source
    ThreatConnect Inc. and Defense Group Inc. (DGI). (2015, September 23). Project CameraShy: Closing the Aperture on China's Unit 78020. Retrieved December 17, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.