Ninja is a Windows trojan and loader framework associated with ToddyCat operations. It has been used in attacks against desktop systems since at least 2021 and provides a broad command set for execution, persistence, traffic relaying, and stealth. Observed delivery includes malicious executable files embedded in ZIP archives and loader packages distributed via Telegram, with victims required to open the embedded executable. Ninja loader components can also be executed through rundll32 and side-loaded through legitimate signed applications, including media player software, using malicious DLLs disguised with benign-looking names.
On compromised hosts, Ninja can establish persistence by creating Windows services masquerading as legitimate components. It supports defense evasion through DLL side-loading, process injection, arbitrary shellcode injection into running processes, and timestomping by altering file access and write times. It can redirect standard input and output through pipes, enabling command execution and output handling across components.
For command and control, Ninja can proxy communications for internal agents, forward TCP packets between command-and-control infrastructure and remote hosts, and build TCP proxy chains of up to 255 hops to obscure operator infrastructure and facilitate pivoting. It can also disguise malicious network traffic by mimicking legitimate services through customized HTTP paths and headers. These characteristics make Ninja a flexible post-compromise platform suited to covert access, internal relaying, and modular payload execution in espionage-oriented intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
a new set of attacks against desktop machines starting in September 2021, named Ninja by the attacker. This Trojan provides a large set of commands
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Cobalt Strike ... Native API; ... Ninja ... Native API; ... Samurai ... Native API
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Ninja ... Obfuscated Files or Information: Compression; ... Samurai ... Obfuscated Files or Information: Compression
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
China Chopper ... Data from Local System; ... Cobalt Strike ... Data from Local System; ... LoFiSe ... Data from Local System; ... Ninja ... Data from Local System; ... Pcexter ... Data from Local System; ... Samurai ... Data from Local System
Examples in the content include malware extracting or unpacking ZIP, RAR, CAB, tar.gz, and other archived content, such as 'Emotet has used a self-extracting RAR file to deliver modules to victims' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
Cobalt Strike ... Data Obfuscation: Protocol or Service Impersonation; ... Ninja ... Data Obfuscation: Protocol or Service Impersonation
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Cobalt Strike ... Proxy: Internal Proxy; ... Ninja ... Proxy: Internal Proxy
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader trojan used to deliver additional payloads and facilitate further compromise of desktop systems.
... Ninja ... (v1.0→v1.1) ...
Ninja (v1.0→v1.1)
Malware that can alter or create last-access and last-write timestamps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.