Neshta is a Windows file-infecting virus active since 2003 that has also been repurposed as a dropper for other malware. It infects executable files on local disks, removable drives, and mapped network shares. Its prepending infection mechanism overwrites the beginning of a host executable and appends the displaced original bytes to the end, encrypting the original executable header. Consequently, removing the viral component alone does not restore an infected file. During execution, Neshta reconstructs the original host in a temporary directory and launches it, preserving the application's apparent functionality.
Neshta establishes persistence by dropping a separate copy of its viral component and changing the Windows executable-opening association so that it runs whenever an executable is opened. It uses a mutex to prevent concurrent instances, checks files for existing infection, and excludes certain directories and file sizes. It can remove read-only attributes before infecting files and uses simple encryption for embedded strings and data.
Neshta has been used to extract, decrypt, and execute HardBit 4.0 ransomware. Red Akodon has also delivered Neshta through phishing campaigns impersonating Colombian judicial institutions, including campaigns distributing remote access trojans. Neshta infections have been observed alongside Vice Society and BlackShadow ransomware activity, although co-occurrence does not establish deliberate deployment by those operators. Its executable-infection behavior is not specific to any industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initial Sample – CVE-2018-8453 ... Kaspersky detailing how Sodin (a.k.a Sodinokibi, or REvil), an infamous ransomware, is using a 1-Day exploit for CVE-2018-8453. | CVE-2018-8453 ... Used by the following malware families: REvil (Sodinokibi), Maze, Neshta.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...artifacts... contain the Neshta malware. This malware aims to modify sections of an executable file and load malicious code.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“install.bat… update.bat… using DACLs via icacls scripting… creates multiple scheduled tasks…”
Another pass to the decryption algorithm reveals the string ‘MutexPolesskayaGlush*.*’, which is used as the name of a mutex created using a call to the CreateMutexA API. This is used to avoid running multiple instances of the malware.
“If the user unzips and executes the contents of the previous file, the malicious activity begins.”
a system infected with Neshta will have the modified registry key ‘HKEY_CLASSES_ROOT\exefile\shell\open\command’ with ‘C:\WINDOWS\svchost.com "%1" %*’. Since C:\WINDOWS\svchost.com is the virus itself, an application will run, with the virus becoming the parent process and the .exe file the child process.
it opens the registry key ‘HKEY_CLASSES_ROOT\exefile\shell\open\command’ using the RegOpenKeyExA API... setting the registry key ‘HKEY_CLASSES_ROOT\exefile\shell\open\command’ with ‘C:\WINDOWS\svchost.com "%1" %*’ as the data value using the RegSetValueExA API.
All of the exploits that we found related to this actor were 1-Day exploits for Local Privilege Escalation (LPE) vulnerabilities in Windows.
“artifacts which seem to be legitimate files but contain the Neshta malware… stored in C:\Windows with the name svchost.com”
the malware attempts to list all the files found in the ‘%temp%\3582-490\’ folder, and tries to delete them one by one, using the DeleteFileA API.
Neshta executes the host file from the ‘%temp%\3582-490\’ folder to avoid raising suspicion that the file is infected, using a call to the ShellExecuteA API.
a system infected with Neshta will have the modified registry key ‘HKEY_CLASSES_ROOT\exefile\shell\open\command’ with ‘C:\WINDOWS\svchost.com "%1" %*’. Since C:\WINDOWS\svchost.com is the virus itself, an application will run, with the virus becoming the parent process and the .exe file the child process.
Using a combination of the FindFirstFileA and FindNextFileA APIs, the malware attempts to list all the files found in the ‘%temp%\3582-490\’ folder... Neshta searches for available drives for infection. It lists the available logical drives in the system using the GetLogicalDriveStringsA API... The malware traverses each folder in each drive searching for executable files for possible infection.
Using the encryption/decryption algorithm discussed earlier, the malware encrypts the first 1,000 (0x3E8) bytes of the recently read data... The data written at the end of the host file includes the newly encrypted 1,000 header bytes and the rest of the first 41,472 (0xA200) bytes of the victim file.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation identified as sharing the Babuk-derived codebase discussed in the article.
A named file-infecting virus reported as frequently accompanying BlackShadow and other Proxima ransomware samples, with similar observations for BlackBit/LokiLocker. The article characterizes it as harmless but does not explain its functionality or establish that operators deliberately deploy it.
File-infecting virus originally discovered in 2003, now repurposed as a dropper to deliver and execute HardBit 4.0 ransomware. Modifies executables and establishes persistence via registry manipulation.
A file infector virus used by MuddyWater.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.