Neursite is a custom modular C/C++ backdoor used in the PassiveNeuron cyberespionage campaign. Kaspersky described it as a custom C++ modular backdoor used against primarily Internet-exposed Windows Server systems at government, financial, and industrial organizations across Asia, Africa, and Latin America, with activity observed from 2024 and renewed infections from December 2024 through at least August 2025. In observed intrusions, attackers in at least one case gained remote code execution through Microsoft SQL Server-related activity, attempted to deploy an ASPX web shell using encoded payloads and scripts, and then used a multi-stage DLL loader chain when web shell deployment failed. Neursite was commonly delivered through Phantom DLL Hijacking-based persistence using oversized malicious DLLs placed in system or service DLL paths such as C:\Windows\System32\wlbsctrl.dll, C:\Windows\System32\TSMSISrv.dll, and C:\Windows\System32\oci.dll; loaders were inflated with junk overlay data, performed MAC-address hash checks to restrict execution, decrypted later stages from Base64/AES-protected data, and in some cases injected into processes such as WmiPrvSE.exe or msiexec.exe. Neursite supports multiple C2 protocols including TCP, SSL, HTTP, and HTTPS, and its configuration can include C2 servers and ports, proxy lists, HTTP headers, a relative URL, beacon timing, an operational schedule, and an optional listening port. Its capabilities include system information collection, process management, proxying traffic through other infected machines to facilitate lateral movement, and plugin support for shell execution, file system management, and TCP socket operations. The campaign also used NeuralExecutor, a custom .NET loader, and Cobalt Strike as a C2 management tool. Attribution remains uncertain, but Kaspersky assessed with low confidence that PassiveNeuron most resembles activity by a Chinese-speaking threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom C/C++ backdoor used in the PassiveNeuron campaign to provide stealthy access and control on compromised Windows Server systems.
Custom C++ modular cyberespionage backdoor used in the PassiveNeuron campaign. Supports TCP/SSL/HTTP/HTTPS C2, can use direct or proxy-based communications, can optionally listen on a port for inbound connections, and supports plugin loading. Core capabilities include system discovery, process management, and proxying traffic through other infected hosts to facilitate lateral movement; observed plugins add shell execution, filesystem management, and TCP socket operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.