PassiveNeuron is a cyberespionage campaign targeting high-profile organizations in government, financial, and industrial sectors across Asia, Africa, and Latin America. The activity has been observed compromising primarily Windows Server systems and deploying custom implants including Neursite and NeuralExecutor, as well as Cobalt Strike in some intrusions. The campaign was first identified in 2024, disrupted mid-2024, and then re-emerged from late 2024 through at least August 2025. The operators have demonstrated server-side intrusion tradecraft consistent with targeted espionage operations. In at least one observed case, they obtained remote code execution through Microsoft SQL Server, then attempted to deploy an ASPX web shell using multiple encoded and scripted delivery variations. When those attempts failed, they shifted to a more elaborate multi-stage loader chain using Phantom DLL Hijacking for persistence. Observed loader chains used oversized DLLs padded with junk data to hinder analysis and detection, victim validation based on hashed MAC addresses to restrict execution, staged decryption of subsequent payloads, and in some cases suspended-process loading to launch later stages. Neursite is a modular C++ backdoor that supports multiple command-and-control protocols, including TCP and web-based channels, and can use either external infrastructure or compromised internal systems. Its functionality includes system information collection, process management, plugin loading, shell execution, file-system operations, and traffic proxying through infected hosts, which can facilitate lateral movement. NeuralExecutor is a .NET implant obfuscated with ConfuserEx that supports several communication mechanisms and is designed to retrieve and execute additional .NET assemblies. In 2025, NeuralExecutor samples were observed using a GitHub-based dead-drop resolver to obtain encrypted command-and-control information. Attribution remains low confidence. The campaign’s tradecraft has been assessed as most closely resembling Chinese-speaking threat actors, including use of techniques previously associated with Chinese espionage activity. A separate malicious DLL observed in related activity also overlapped with artifacts previously discussed in reporting on suspected APT41-linked operations. Despite these similarities, no definitive public attribution is established. Known malware associated with the campaign includes Neursite and NeuralExecutor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PassiveNeuron is conducting cyber espionage campaigns targeting government, industrial, and financial organizations across multiple continents using custom malware implants.
A targeted cyberespionage activity cluster focused on compromising primarily Windows Server systems (including Microsoft SQL servers) at government, financial, and industrial organizations. Uses multi-stage DLL loader chains with persistence via Phantom DLL Hijacking, anti-sandbox MAC-address checks, and deploys custom implants (Neursite, NeuralExecutor) plus Cobalt Strike; observed 2024 and renewed activity Dec 2024–Aug 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.