Neutrino is a Windows botnet malware family also known as Kasidet and MWZLesson. Its capabilities include distributed denial-of-service attacks, credential theft, and downloading additional malware. It has been delivered by the Sundown exploit kit and by Smoke Loader. In an observed multistage infection chain, Neutrino downloaded multiple Lethic spambot payloads after being installed by Smoke Loader.
Neutrino has used Namecoin-based domain resolution for command-and-control communications. Some variants incorporate a Monero-mining module and emphasize downloading and executing additional modules. The family is associated with financially motivated cybercrime and has appeared in TA505's malware arsenal.
Neutrino malware is distinct from the similarly named Neutrino exploit kit, a browser-exploitation framework used to deliver other malware. Exploitation techniques and malvertising campaigns attributed to that kit should not be treated as capabilities or distribution activity of the botnet family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This is a new Exploit Kit, dubbed neutrino, identified in the wild by Kafeine. ... It uses two Java vulnerabilities: CVE-2012-1723 CVE-2013-0431.
This is a new Exploit Kit, dubbed neutrino, identified in the wild by Kafeine. ... It uses two Java vulnerabilities: CVE-2012-1723 CVE-2013-0431.
When Angler disappeared from the exploit kit market, the “GooNky” actors migrated their malvertising campaign to Neutrino EK. Within a few days after this migration, the code allowing exploitation of this bug was integrated into Neutrino.
...six zero-day vulnerabilities (... CVE-2015-5119, CVE-2015-5122 and CVE-2015-5123 for Adobe Flash; ...) ... being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5122 ... for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5123 for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-2425 for Internet Explorer) ... being released into the wild.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In 2021 OPERA1ER changed arsenal RATs to: Neutrino, BlackNET, bitrat and 888_rat, Venom RAT.”
When Angler disappeared from the exploit kit market, the “GooNky” actors migrated their malvertising campaign to Neutrino EK. Within a few days after this migration, the code allowing exploitation of this bug was integrated into Neutrino.
Their arsenal includes the Dridex banking trojan, Neutrino botnet, as well as Locky, Jaff, GlobeImposter, and other ransomware.
Initially, the gang behind AdGholas had been using the Angler and Neutrino exploit kits.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The list is encoded at Base64. After decoding, the Trojan tries to find a working C&C... We should also notice that in the header of each POST-request there is “auth” field... The server sends commands in plain view, like “PROXY”, “screenshot” and so on, encoded in base64.
The Trojans start to work through currently running processes, using CreateToolhelp32Snapshot\ Process32FirstW\Process32NextW .
The Trojan scans the memory pages for string “Track1”, which marks fields of the first track of the magnetic card... Collected data sends to server with mark “Track1” ... After that, the Trojan starts to extracts next fields with mark “Track2”
These C&C servers enabled and controlled online crime such as credential theft... They were also used for the retrieval of stolen data.
45.77.141[.]25 port 80 - eeaglelifedd[.]com - POST /hosting20/ ... 118.193.174[.]133 port 80 - n31.smokemenowhhalala[.]bit - POST /newfiz31/logout.php
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit used to automate discovery and exploitation of known software vulnerabilities for malware delivery.
A follow-on trojan/downloader delivered by Smoke Loader that checks in to attacker infrastructure and retrieves additional payloads, in this case multiple Lethic spambot binaries.
Botnet named as part of TA505's historical arsenal. The article provides no further technical details.
A malware family associated with botnet controllers, described as both a DDoS bot and credential stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.