Nebulae is a Windows backdoor used by the Naikon threat group in cyber-espionage operations against military organizations and telecommunications providers in Southeast Asia. It was observed in military-targeting campaigns conducted between June 2019 and March 2021 and alongside the Aria-Body loader and RainyDay backdoor. RainyDay has also been used to deploy Nebulae on compromised systems.
Nebulae supports system and drive information collection, file and directory enumeration, file movement and deletion, process execution, process listing and termination, and bidirectional file transfers with command-and-control servers. These functions enable remote control, host reconnaissance, and exfiltration of collected files. Its command-and-control communications use TCP with RC4-encrypted payloads, while samples also use XOR to obfuscate command-and-control configuration data.
Nebulae exists in executable and DLL forms. Attackers execute its DLL variants through side-loading by legitimate applications, including browser components and security software. Some variants imitate legitimate browser-library exports to appear benign. Persistence mechanisms include registry-based logon autostart entries and Windows services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The second backdoor, that we call Nebulae, is supposedly used as a measure of precaution to not lose the persistence in case any signs of infections gets detected.
BRONZE GENEVA is likely responsible for part of this activity based on overlap between the C2 infrastructure for the Nebulae malware family associated with BRONZE GENEVA and a ShadowPad sample analyzed by CTU researchers.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
the config section that appears to be obfuscated by XOR-ing with the 0x2D value.
The findings reveal their strategy to remain stealthy by mimicking legitimate applications that are running on individual infected machines.
Malicious service “sstpsvces” mimics the legitimate Secure Socket Tunneling Protocol Service(SstpSvc)
vmtools.exe that differs by one letter from the legitimate executable vmtoolsd.exe.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BRONZE GENEVA; referenced due to C2 infrastructure overlap with ShadowPad activity.
A backdoor used for persistence and remote control. It performs reconnaissance, file and process manipulation, arbitrary command execution, privilege escalation, and C2 communications using raw sockets with RC4-encrypted traffic.
Can use TCP for command-and-control communications.
Enterprise New Software: ... Nebulae
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.