NeuralExecutor is a custom .NET implant/loader used in the PassiveNeuron cyberespionage campaign. It has been described by Kaspersky as a custom .NET implant used for running additional .NET payloads and as a loader that can fetch, load, and execute additional .NET assemblies received from command-and-control infrastructure. Observed samples were obfuscated with ConfuserEx. NeuralExecutor supports multiple communication mechanisms including TCP, HTTP/HTTPS, named pipes, and WebSockets. In 2025 variants, it used a GitHub-based dead drop resolver to retrieve C2 data delimited by the strings "wtyyvZQY" and "stU7BU0R," then Base64-decoded and AES-decrypted that data to obtain the C2 address. Kaspersky noted this delimiter-based GitHub C2 retrieval pattern resembles tradecraft used by Chinese-speaking threat actors, but attribution remains low confidence.
NeuralExecutor was observed alongside the custom C++ backdoor Neursite and Cobalt Strike in PassiveNeuron intrusions. The campaign targeted primarily Windows Server systems at government, financial, and industrial organizations across Asia, Africa, and Latin America, with activity observed from 2024 and a renewed wave from December 2024 through at least August 2025. In at least one case, attackers gained remote code execution through Microsoft SQL Server-related access, then attempted to deploy an ASPX web shell using encoded payloads and scripting. When web shell deployment failed, operators used a multi-stage DLL loader chain with Phantom DLL Hijacking for persistence, placing malicious DLLs in system paths such as C:\Windows\System32\wlbsctrl.dll, C:\Windows\System32\TSMSISrv.dll, and C:\Windows\System32\oci.dll. These loaders were often artificially inflated to very large sizes with junk overlay data, included MAC-address-based execution checks, and ultimately loaded Neursite, NeuralExecutor, or Cobalt Strike. High-confidence related indicators and traits include the use of ConfuserEx obfuscation, GitHub dead-drop C2 resolution in 2025 samples, and operation within the PassiveNeuron intrusion chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom .NET loader used in the PassiveNeuron campaign, including variants that retrieve C2 configuration or next-stage URLs from public GitHub content as a dead-drop resolver.
Custom .NET implant used in PassiveNeuron primarily to receive and execute additional .NET assemblies. Uses ConfuserEx obfuscation and supports multiple C2 channels (TCP, HTTP/HTTPS, named pipes, WebSockets). 2025 variants use a GitHub-based dead-drop resolver: fetch a file, extract a delimited blob, then Base64-decode and AES-decrypt it to recover C2 addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.