Neoichor

S0691

Malware.View on attack.mitre.org

About this malware

Neoichor is C2 malware used by Ke3chang since at least 2019; similar malware families used by the group include Leeson and Numbldea.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1005
Data from Local System

Neoichor can upload files from a victim's machine.

T1016
System Network Configuration Discovery

Neoichor can gather the IP address from an infected host.

T1016.001
Internet Connection Discovery

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

T1033
System Owner/User Discovery

Neoichor can collect the user name from a victim's machine.

T1070
Indicator Removal

Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key.

T1071.001
Web Protocols

Neoichor can use HTTP for C2 communications.

T1082
System Information Discovery

Neoichor can collect the OS version and computer name from a compromised host.

T1105
Ingress Tool Transfer

Neoichor can download additional files onto a compromised host.

T1112
Modify Registry

Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`.

T1559.001
Component Object Model

Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2.

T1614.001
System Language Discovery

Neoichor can identify the system language on a compromised host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft NICKEL December 2021 Open source
    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.