NOKKI

S0353

Malware.View on attack.mitre.org

About this malware

NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

NOKKI can gather information on the victim IP address.

T1027
Obfuscated Files or Information

NOKKI uses Base64 encoding for strings.

T1033
System Owner/User Discovery

NOKKI can collect the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location

NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.

T1056.004
Credential API Hooking

NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.

T1070.004
File Deletion

NOKKI can delete files to cover tracks.

T1071.001
Web Protocols

NOKKI has used HTTP for C2 communications.

T1071.002
File Transfer Protocols

NOKKI has used FTP for C2 communications.

T1074.001
Local Data Staging

NOKKI can collect data from the victim and stage it in LOCALAPPDATA%\MicroSoft Updatea\uplog.tmp.

T1082
System Information Discovery

NOKKI can gather information on the operating system on the victim’s machine.

T1105
Ingress Tool Transfer

NOKKI has downloaded a remote module for execution.

T1124
System Time Discovery

NOKKI can collect the current timestamp of the victim's machine.

T1140
Deobfuscate/Decode Files or Information

NOKKI uses a unique, custom de-obfuscation technique.

T1218.011
Rundll32

NOKKI has used rundll32 for execution.

T1547.001
Registry Run Keys / Startup Folder

NOKKI has established persistence by writing the payload to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Unit 42 NOKKI Sept 2018 Open source
    Grunzweig, J., Lee, B. (2018, September 27). New KONNI Malware attacking Eurasia and Southeast Asia. Retrieved November 5, 2018.
  2. Unit 42 Nokki Oct 2018 Open source
    Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.