nccTrojan, also known as MsmRAT, is a Windows remote access trojan used by the China-linked cyberespionage group TA428, also tracked as BRONZE DUDLEY. It has been observed since at least March 2019 and is associated with Operation LagTime IT. Targets include East Asian government organizations and defense and aviation organizations in Russia and Mongolia. It was also deployed in a 2022 espionage campaign targeting defense-related enterprises and public institutions in Belarus, Russia, Ukraine, and Afghanistan.
The malware supports remote shells, operating-system command and program execution, disk and file enumeration, process listing and termination, bidirectional file transfer, and file management, including deletion, copying, and moving. These functions enable remote control, host reconnaissance, and exfiltration of confidential files.
Two major branches differ in deployment and communications. Version 1 can be delivered during initial intrusion through Royal Road-generated malicious RTF documents and uses XOR-obfuscated command-and-control traffic. Version 2 is generally deployed after lateral movement and acquisition of elevated privileges, including through existing Poison Ivy or PortDoor infections. An installer registers its DLL payload as an automatically starting Windows service masquerading as a legitimate system component. Version 2 uses a custom TCP protocol with AES-encrypted payloads and requires a configured activation code before accepting backdoor commands. Version 2.45, identified in January 2022, selects the first responding configured command-and-control server and reports host and user information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit MS17-010 for lateral movement, NETBIOS scanner for environmental investigations, tools to steal credentials and new RATs such as Tmanger or nccTrojan.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2022, we identified a new, improved version of nccTrojan – 2.45.
BRONZE DUDLEY ... Tools ... NCCTrojan, PhantomNet, PoisonIvy, Royal Road
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Tmanger has following functions: Remote Shell (cmd.exe); Remote Shell (powershell.exe)... nccTrojan has following functions: Remote Shell.
v1は単純なXORであるため復号は容易ですが、v2は多少複雑な構造となっています。... DATAフィールドはAESによって暗号化されています。
Configuration data lists C&C servers on ports 443, 8080, 80, and 5222; sections describe C&C communication for Poison Ivy, Tmanger, and nccTrojan.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE DUDLEY threat profile.
Backdoor providing remote system control and file exfiltration. Attackers download its DLL through PortDoor infrastructure, unpack it from a CAB archive, and register it as a service for persistence. Version 2.45 reports system information and communicates with the first responding server among its hard-coded command-and-control addresses. January 2022 identifies discovery of this version, not the family's first discovery.
TA428が使用するRAT/バックドア。v1とv2の主要バージョンがあり、初期侵入段階でも横展開後でも使われる。ファイル操作、リモートシェル、プロセス操作、ファイル転送、プログラム実行などの機能を備え、v2はサービス登録され独自TCPとAES暗号化通信を用いる。
A trojan used by TA428 in attacks against East Asian organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.