Wild Neutron, also known as Morpho and Jripbot, is a long-running espionage threat actor active since at least 2011. The group became widely known for 2013 watering-hole operations against high-profile technology targets including Apple, Facebook, Twitter, and Microsoft, and later continued with highly selective intrusions through 2014 and 2015. Targeting has included law firms, Bitcoin-related businesses, investment firms, large corporate groups involved in mergers and acquisitions, information technology companies, healthcare organizations, real estate companies, and individual users. Victim distribution across multiple countries and sectors, combined with the nature of the intrusions, is consistent with espionage activity and has also led some researchers to assess a possible mercenary or economically motivated profile rather than a clearly attributable state-directed mission. The actor has used exploits, watering-hole compromises, and multi-platform malware, including Windows, macOS, and Linux tooling. Publicly documented operations included use of a Java zero-day in 2013 and evidence of an unknown Flash Player exploit in later activity. Wild Neutron’s malware ecosystem centered on the Jripbot backdoor and related components, supported by loaders, droppers, information-gathering modules, reverse-shell capability, credential theft tooling, and custom OpenSSH-based tunneling utilities for exfiltration. The group also used a malware dropper signed with a stolen legitimate code-signing certificate. Wild Neutron’s tradecraft includes custom encrypted command-and-control communications, anti-sandbox and anti-emulation checks, modular plugin-based architecture, obfuscation of payloads and strings, victim-specific fallback resolution, and extensive post-compromise tooling. Documented capabilities include host reconnaissance, shell command execution, persistence, file shredding, plugin deployment, password harvesting, screenshots, reverse shell access, port scanning, and use of customized implementations of common administrative or offensive tools for credential collection and movement within victim environments. The actor has also reused open-source software, Metasploit components, and leaked malware source code, and has shown familiarity with Unix-style tooling through Cygwin-ported utilities. Wild Neutron is notable for disciplined, targeted operations against a relatively small number of systems per victim organization and for reliable data theft mechanisms, particularly SSH-based tunnels used for large-scale exfiltration. Language artifacts observed in samples have included Romanian and Russian strings, but these are not sufficient for confident attribution. No high-confidence country of origin is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Instead of Flash exploits, older Wild Neutron exploitation and watering holes used what was a Java zero-day at the end of 2012 and the beginning of 2013, detected by Kaspersky Lab products as Exploit.Java.CVE-2012-3213.b.
Their arsenal included multi-platform malware [9], a Java zero-day (CVE20130422), and a penchant for well-chosen watering-hole sites.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Elusive actor known for attacks on major technology companies, using innovative tooling including custom Linux backdoors, LSA backdoors, IIS plugins, and zero-days.
Espionage-focused intrusion activity against high-profile companies using watering holes, zero-day exploits, multi-platform malware, stolen code-signing certificates, modular backdoors, and SSH-based exfiltration; likely economically motivated rather than nation-state sponsored according to the content.
Conducted broad, likely mercenary-style intrusions across multiple industries and countries using watering holes, multi-platform malware, and a Java zero-day, while leaving contradictory attribution clues.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.