NKAbuse

S1107

Malware.View on attack.mitre.org

About this malware

NKAbuse is a Go-based, multi-platform malware abusing NKN (New Kind of Network) technology for data exchange between peers, functioning as a potent implant, and equipped with both flooder and backdoor capabilities.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1016.001
Internet Connection Discovery

NKAbuse utilizes external services such as ifconfig.me to identify the victim machine's IP address.

T1053.003
Cron

NKAbuse uses a Cron job to establish persistence when infecting Linux hosts.

T1057
Process Discovery

NKAbuse will check victim systems to ensure only one copy of the malware is running.

T1059.004
Unix Shell

NKAbuse is initially installed and executed through an initial shell script.

T1082
System Information Discovery

NKAbuse conducts multiple system checks and includes these in subsequent "heartbeat" messages to the malware's command and control server.

T1090.003
Multi-hop Proxy

NKAbuse has abused the NKN public blockchain protocol for its C2 communications.

T1113
Screen Capture

NKAbuse can take screenshots of the victim machine.

T1498
Network Denial of Service

NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. NKAbuse BC Open source
    Bill Toulas. (2023, December 14). New NKAbuse malware abuses NKN blockchain for stealthy comms. Retrieved February 8, 2024.
  2. NKAbuse SL Open source
    KASPERSKY GERT. (2023, December 14). Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol. Retrieved February 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.