NGLite is a Go-based backdoor trojan associated with China-linked intrusion activity, including operations attributed to APT27. It has been observed in post-exploitation chains following exploitation of Zoho ManageEngine ADSelfService Plus, where operators deployed web shells and additional tooling before installing NGLite on compromised servers. The malware is notable for using the NKN decentralized networking protocol for command-and-control communications, a technique that helps obscure operator infrastructure and has also been seen in other malware families.
NGLite supports remote command execution and basic host reconnaissance. Documented behavior includes executing the whoami command to collect system user context and returning the result to its command-and-control channel. Its role in observed intrusions was to provide persistent remote access after initial compromise, enabling follow-on espionage activity alongside credential theft and information-stealing tools such as KdcSponge. Reported victim sectors in related campaigns included healthcare, defense, energy, technology, education, consulting, and IT, with compromises spanning multiple regions.
NGLite has been publicly described as distinct from later NKN-based malware such as NKN-goRAT, despite superficial overlap in use of NKN for command and control. High-confidence reporting characterizes NGLite specifically as a backdoor trojan written in Go and used as part of targeted state-linked post-compromise operations rather than broad commodity distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
In 2021, APT27 targeted multiple industries... by exploiting REST API authentication bypass in Zoho ManageEngine ADSelfService Plus (CVE-2021-40539), resulting in the compromise of at least nine organizations worldwide. Operators scanned vulnerable ADSelfService Plus servers... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer. | Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
APT27 gains initial access through a range of well-documented and opportunistic methods. The group has consistently exploited vulnerabilities in internet-facing applications, including high-profile cases like Zoho ManageEngine ADSelfService Plus (CVE-2021-40539) and Microsoft Exchange ProxyLogon/ProxyShell (CVE-2021-26855/-26857/-26858/-27065). They also targeted Apache Tomcat servers using Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45105).
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
AsyncRAT can proxy C2 through a Tor client. Attor has used Tor for C2 communication. Cyclops Blink has used Tor nodes for C2 traffic. GreyEnergy has used Tor relays for Command and Control servers. Siloscape uses Tor to communicate with C2. WannaCry uses Tor for command and control traffic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan deployed by APT27 during Zoho ManageEngine exploitation campaigns.
Referenced for comparison as prior malware abusing the NKN protocol.
A named tool previously used alongside Godzilla in related ManageEngine ADSelfService Plus intrusions by the same activity cluster; specific functionality is not described in this content beyond being part of the actor’s tooling.
Backdoor that abuses NKN infrastructure for command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.