Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. NGLite

NGLite

NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.[1]

ID: S1106
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 08 February 2024
Last Modified: 19 April 2024
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003.[1]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

NGLite will use an AES encrypted channel for command and control purposes, in one case using the keyWHATswrongwithUu.[1]

EnterpriseT1090.003Proxy:Multi-hop Proxy

NGLite has abused NKN infrastructure for its C2 communication.[1]

EnterpriseT1016System Network Configuration Discovery

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.[1]

EnterpriseT1033System Owner/User Discovery

NGLite will run thewhoami command to gather system information and return this to the command and control server.[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp