NICECURL is malware used by the Iranian state-aligned threat actor APT42. The provided content associates it with APT42 operations and identifies it as part of malware-based activity documented alongside families such as TAMECAT, BASICSTAR, CharmPower, GORBLE, GorjolEcho, and POWERSTAR. High-confidence reporting in the content states that NICECURL communicates with command-and-control infrastructure over HTTPS and provides an arbitrary command execution interface, indicating use as a remote access/backdoor capability for operator tasking on compromised systems. The content does not provide a detailed infection vector, persistence mechanism, or specific indicators of compromise unique to NICECURL, but places it within APT42 espionage activity targeting victims of interest to that actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Google / Mandiant documents APT42 operating multiple infrastructure clusters in parallel and abusing Google Sites to funnel victims to fake logins, alongside NICECURL and TAMECAT malware-based operations...
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT41 DUST used HTTPS for command and control. APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. Lumma Stealer has used HTTPS for command and control purposes.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Details and IOCs Malware: BASICSTAR, CharmPower, GORBLE, GorjolEcho, NICECURL, POWERSTAR, TAMECAT
A malware/tool family referenced as part of prior APT42 operations and used for comparison with the observed tradecraft in this campaign.
Malware/tool that uses HTTPS for command-and-control communications.
Backdoor malware that exposes an interface for arbitrary command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.