ATT&CKReferencesNGLite Trojan

NGLite Trojan

Robert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNGLite

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.

T1033
System Owner/User Discovery
MalwareNGLite

NGLite will run the whoami command to gather system information and return this to the command and control server.

T1071.001
Web Protocols
MalwareNGLite

NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003.

T1090.003
Multi-hop Proxy
MalwareNGLite

NGLite has abused NKN infrastructure for its C2 communication.

T1573.001
Symmetric Cryptography
MalwareNGLite

NGLite will use an AES encrypted channel for command and control purposes, in one case using the key WHATswrongwithUu.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.