NICECURL is a custom VBScript backdoor used by the Iranian state-sponsored cyberespionage group APT42 against Windows systems. It provides arbitrary command execution and downloads and executes additional modules for data mining and other operator-directed tasks, enabling sensitive-data theft from compromised hosts. The backdoor communicates with command-and-control infrastructure over HTTPS. Its command interface supports downloading additional files, changing its sleep interval, and removing artifacts before terminating execution.
APT42 has delivered NICECURL through malicious emails in targeted spear-phishing operations, including campaigns that impersonate journalists to establish trust with victims. These operations have targeted organizations in Western and Middle Eastern countries, including media outlets, nongovernmental organizations, academic institutions, legal services, and activist groups. NICECURL has been deployed alongside TAMECAT as part of APT42's malware-based espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers used malicious emails to deliver two custom backdoors, named Nicecurl and Tamecat, which allowed them to execute commands and steal sensitive data from the compromised systems.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
NICECURL's accepted commands include "kill" to remove artifacts and end execution.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT41 DUST used HTTPS for command and control. APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. Lumma Stealer has used HTTPS for command and control purposes.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Details and IOCs Malware: BASICSTAR, CharmPower, GORBLE, GorjolEcho, NICECURL, POWERSTAR, TAMECAT
A malware/tool family referenced as part of prior APT42 operations and used for comparison with the observed tradecraft in this campaign.
Custom backdoor delivered through malicious emails in APT42 social-engineering campaigns. Enables command execution and theft of sensitive data from compromised systems.
Malware/tool that uses HTTPS for command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.