Neutrino is a Windows malware family associated with multiple distinct criminal use cases over time, including operation as an exploit kit and as a bot or trojan family linked to credential theft, banking activity, distributed denial-of-service functionality, and modular payload delivery. It has also been referenced under aliases including Kasidet and MWZLesson in infrastructure tracking related to Namecoin-based command-and-control usage.
Neutrino has been observed in multi-stage infection chains as a follow-on payload delivered by other malware such as Smoke Loader, after which it retrieved additional malware families including the Lethic spambot. In these cases it functioned as an intermediate downloader or loader, maintaining communications with command-and-control infrastructure and fetching subsequent payloads for spam or other criminal operations. It has also been reported as a payload delivered by the Sundown exploit kit.
Separate reporting has described Neutrino as a DDoS bot and credential stealer, and later as a banking-trojan variant that incorporated a Monero mining module and emphasized modular download-and-execute behavior. Neutrino-related activity has also been tied to exploit-kit ecosystems and malvertising operations; operators behind the AdGholas campaign previously used the Neutrino exploit kit before shifting to other exploit frameworks. More broadly, Neutrino has been cited among common exploit kits used to compromise vulnerable systems through browser and plugin exploits.
The malware targets Windows systems and has been associated with financially motivated cybercrime, including spam distribution, credential theft, banking fraud, and opportunistic monetization through cryptomining. Its observed use of Namecoin .bit domains for command-and-control reflects an effort to improve resilience and complicate takedown or tracking of its infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...six zero-day vulnerabilities (... CVE-2015-5119, CVE-2015-5122 and CVE-2015-5123 for Adobe Flash; ...) ... being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5122 ... for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5123 for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-2425 for Internet Explorer) ... being released into the wild.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Initially, the gang behind AdGholas had been using the Angler and Neutrino exploit kits.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The list is encoded at Base64. After decoding, the Trojan tries to find a working C&C... We should also notice that in the header of each POST-request there is “auth” field... The server sends commands in plain view, like “PROXY”, “screenshot” and so on, encoded in base64.
The Trojans start to work through currently running processes, using CreateToolhelp32Snapshot\ Process32FirstW\Process32NextW .
The Trojan scans the memory pages for string “Track1”, which marks fields of the first track of the magnetic card... Collected data sends to server with mark “Track1” ... After that, the Trojan starts to extracts next fields with mark “Track2”
These C&C servers enabled and controlled online crime such as credential theft... They were also used for the retrieval of stolen data.
45.77.141[.]25 port 80 - eeaglelifedd[.]com - POST /hosting20/ ... 118.193.174[.]133 port 80 - n31.smokemenowhhalala[.]bit - POST /newfiz31/logout.php
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit used to automate discovery and exploitation of known software vulnerabilities for malware delivery.
A follow-on trojan/downloader delivered by Smoke Loader that checks in to attacker infrastructure and retrieves additional payloads, in this case multiple Lethic spambot binaries.
A malware family associated with botnet controllers, described as both a DDoS bot and credential stealer.
Malware associated with botnet controllers; described as both a DDoS bot and credential stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.