NativeZone is a custom Windows malware component associated with NOBELIUM, the Russia-linked espionage actor also tracked in connection with the SolarWinds intrusion. It has been described as a custom Cobalt Strike Beacon loader and backdoor used in phishing-led intrusion chains targeting government agencies, NGOs, think tanks, consultants, and other organizations of intelligence interest. Observed campaigns included abuse of trusted email distribution infrastructure and socially engineered lures that delivered malicious content requiring user interaction.
NativeZone has been used as part of a staged infection chain in which a victim opens attacker-delivered content that ultimately launches a malicious DLL through rundll32 and executes Cobalt Strike Beacon shellcode. The malware can decrypt and decode embedded Beacon stage shellcode and has displayed decoy content, including RTF documents, to facilitate or mask execution. It has also shown a message box themed to appear related to a Ukrainian electronic document management system, indicating use of masquerading and social-engineering elements to reduce suspicion.
The malware includes execution guardrails: it checks for the presence of a specific DLL in the same directory as its components and halts if that condition is not met. This behavior is consistent with environment validation and controlled execution to avoid unintended detonation or analysis. Once deployed, NativeZone supports post-compromise activity by establishing a backdoor foothold through Cobalt Strike, enabling follow-on operations such as data theft and movement within victim environments. NativeZone is therefore best understood as a Windows loader/backdoor used in targeted espionage operations, tightly integrated into NOBELIUM phishing campaigns and Beacon-based post-exploitation workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"If the device targeted was an Apple iOS device, the user was redirected to another server under NOBELIUM control, where the since-patched zero-day exploit for CVE-2021-1879 was served."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...a DLL... that is a custom Cobalt Strike Beacon loader dubbed NativeZone by Microsoft... Microsoft Defender Antivirus detects... Trojan:Win32/NativeZone.C!dha
13 distinct techniques documented for this family, organized by ATT&CK tactic.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
“…included a link that, when clicked, inserted a malicious file used to distribute a backdoor…”
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
“The end result when detonating the LNK file is the execution of ‘C:\Windows\system32\rundll32.exe Documents.dll,Open’.”
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enterprise New Software: ... NativeZone
Malware that decrypts and decodes embedded Cobalt Strike Beacon stage shellcode.
Malware that displays an RTF decoy to facilitate execution of follow-on payload shellcode.
Early-stage tool/malware in NOBELIUM toolset (per Microsoft).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.