LightNeuron is a sophisticated backdoor attributed to the Russian state-linked Turla espionage group and purpose-built for Microsoft Exchange email servers. It operates as a malicious mail transfer agent embedded in Exchange mail flow, giving operators control over messages transiting an infected server. Its functionality includes intercepting, reading, redirecting, modifying, composing, and blocking email, making it an email-server implant tailored for long-term espionage against diplomatic and government-related targets.
The malware has been publicly associated with compromises of organizations including diplomatic and foreign affairs entities, and it has been reported in use since at least 2014. LightNeuron is notable for using an email-based command-and-control model rather than requiring direct operator connections to the compromised server. Commands can be concealed in image or document attachments using steganographic techniques, and the malware encrypts command-and-control traffic with AES. It also uses AES and XOR routines to decrypt configuration data and commands.
LightNeuron supports collection and exfiltration of data from the local system and from Exchange itself. It can automatically collect files from specified directories, gather emails matching configured rules, encrypt and store collected emails, and exfiltrate data over its email command-and-control channel. It also performs host discovery functions such as enumerating network adapter information via Windows APIs. Additional capabilities include deleting files and starting processes through native Windows process-creation APIs, indicating support for broader post-compromise activity beyond mail interception alone.
The malware employs defense-evasion measures by masquerading its components with names associated with Microsoft Exchange and Outlook. Its deep integration into Exchange makes removal difficult and supports stealthy persistence on targeted mail infrastructure. LightNeuron is primarily associated with Windows-based Microsoft Exchange server environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2019-05-07 ⋅ ESET Research Turla LightNeuron: An email too far LightNeuron
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the technique of steganography, Turla hackers hide commands inside PDF and JPG images, which the backdoor reads and then executes.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Using the technique of steganography, Turla hackers hide commands inside PDF and JPG images, which the backdoor reads and then executes.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
LightNeuron allows hackers to have full control over everything that passes through an infected email server, having the ability to intercept, redirect, or edit the content of incoming or outgoing emails.
LightNeuron allows hackers to have full control over everything that passes through an infected email server, having the ability to intercept, redirect, or edit the content of incoming or outgoing emails.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turla backdoor targeting email infrastructure, described as enabling remote code execution via email workflows.
LightNeuron is an Exchange backdoor used by the Turla threat actor group, capable of interacting with Cobalt Strike beacons over email.
Gathers network adapter information using GetAdaptersInfo.
Backdoor malware that uses AES and XOR to decrypt configuration files and commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.