Nemucod is a malware family best known as an obfuscated JavaScript downloader used in large-scale spam campaigns to deliver additional payloads onto Windows systems. It has been widely distributed through malicious email attachments, commonly using invoice-themed lures and compressed archives that contain JavaScript rather than a native executable, a technique used to evade some mail filtering and user suspicion. Early naming of the family is associated with download paths containing a reversed form of the word “document.”
Nemucod’s primary role is to retrieve and execute second-stage malware from remote infrastructure. Reported payloads delivered by Nemucod include ransomware such as Locky and TeslaCrypt, banking malware such as Dridex, and trojans such as Emotet. In observed campaigns, the JavaScript downloader used heavy obfuscation, randomly named variables, and encoded address data, then fetched an executable payload and launched it on the victim host.
The family has been associated with high-volume malspam operations affecting multiple regions globally, with particularly notable activity in Europe and Japan during major campaigns. Nemucod has also appeared as an initial delivery component in operations leading to follow-on malware such as BackSwap and Ozone RAT. Its operational value lies in flexible payload delivery rather than complex post-compromise functionality of its own.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of finding an EXE file, the ZIP container has a Javascript file inside. This technique might have been used by the attackers to avoid detection in some mail scanners and reach as many victims as possible.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spam-delivered downloader trojan that retrieves additional payloads including Locky ransomware and Dridex.
A named loader mentioned as an example of a malware family name derived by reversing a string found in infrastructure or artifacts.
Referenced in detection naming for the dropped JavaScript file used in the infection chain as a downloader/dropper component.
A JavaScript downloader family used in spam campaigns to deliver the banking malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.