Nebulae

S0630

Malware.View on attack.mitre.org

About this malware

Nebulae Is a backdoor that has been used by Naikon since at least 2020.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Nebulae has the capability to upload collected files to C2.

T1036.004
Masquerade Task or Service

Nebulae has created a service named "Windows Update Agent1" to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

Nebulae uses functions named StartUserModeBrowserInjection and StopUserModeBrowserInjection indicating that it's trying to imitate chrome_frame_helper.dll.

T1057
Process Discovery

Nebulae can enumerate processes on a target system.

T1059.003
Windows Command Shell

Nebulae can use CMD to execute a process.

T1070.004
File Deletion

Nebulae has the ability to delete files and directories.

T1083
File and Directory Discovery

Nebulae can list files and directories on a compromised host.

T1095
Non-Application Layer Protocol

Nebulae can use TCP in C2 communications.

T1105
Ingress Tool Transfer

Nebulae can download files from C2.

T1106
Native API

Nebulae has the ability to use CreateProcess to execute a process.

T1543.003
Windows Service

Nebulae can create a service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder

Nebulae can achieve persistence through a Registry Run key.

T1573.001
Symmetric Cryptography

Nebulae can use RC4 and XOR to encrypt C2 communications.

T1574.001
DLL

Nebulae can use DLL side-loading to gain execution.

T1680
Local Storage Discovery

Nebulae can discover logical drive information including the drive type, free space, and volume information.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Bitdefender Naikon April 2021 Open source
    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.