Aria-Body, also known as AR, is a Windows DLL backdoor family used by the Naikon threat actor in cyber-espionage operations targeting government, legislative, law-enforcement, military, and intelligence organizations in Southeast Asia and the South China Sea region. Variants analyzed from 2017–2018 share code with Naikon components used since at least 2012. Loader components decrypt configuration data and payload DLLs and inject the backdoor into other processes, allowing portions of the malware to operate in memory without being written to disk. It supports persistence through Windows startup mechanisms and registry-based autostart configuration.
Aria-Body provides remote access, shell and process management, file and directory manipulation, file execution through native Windows APIs, and download management. Its reconnaissance capabilities include enumerating loaded process modules and identifying the current username, host domain, public IP address, and geographic location. It can capture screenshots and delete files and directories; newer variants introduced raw-input-based keylogging in February 2018. Command-and-control capabilities include TCP and HTTP communications and domain generation algorithms for dynamically resolving command-and-control destinations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bitdefender confidently attributed this operation to the Naikon threat actor based on command-and-control servers and malicious payloads belonging to the Aria-Body loader malware family used in the group's past operations.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Aria-body ... (v1.2→v1.3) ...
Aria-body (v1.2→v1.3)
Malware referenced as using the process module enumeration technique described in the article.
Backdoor capable of identifying the username on a compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.