Malware.View on attack.mitre.org
NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier. |
| T1033 System Owner/User Discovery |
NGLite will run the |
| T1071.001 Web Protocols |
NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003. |
| T1090.003 Multi-hop Proxy |
NGLite has abused NKN infrastructure for its C2 communication. |
| T1573.001 Symmetric Cryptography |
NGLite will use an AES encrypted channel for command and control purposes, in one case using the key |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.