NanHaiShu is a Windows JavaScript backdoor associated with Chinese state-linked cyber-espionage activity, including operations attributed to APT40 and long-running campaigns focused on maritime, defense, government, legal, and research organizations. It has been used in targeted intrusion activity against entities connected to naval and South China Sea interests, typically as part of spearphishing-led infection chains that leverage malicious documents, exploit-enabled lures, or script-based execution.
The malware uses mshta.exe as a signed proxy execution mechanism to load its components and can execute additional JScript and VBScript on compromised hosts. It establishes persistence by modifying Windows Registry Run key autostart settings. NanHaiShu performs host and network reconnaissance by collecting the current username, computer name, serial number, and proxy configuration details. It communicates with command-and-control infrastructure over DNS and can download additional files for follow-on activity.
NanHaiShu also includes defense-evasion and anti-forensic behavior. It can alter Internet Explorer settings to reduce security warnings that might expose malicious activity, and it has been observed launching scripts to delete decoy documents used during infection in order to remove evidence. Reported functionality also includes Base64 encoding of files or data. Overall, NanHaiShu is best characterized as a script-based espionage backdoor used for persistence, reconnaissance, staged payload delivery, and covert command-and-control on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor is a fairly involved script malware. Its functionality includes: Overwriting registry settings to reduce malware visibility on system
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Use simple obfuscation such as base64, gzip compression, and insertion of garbage characters
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Executes additional VBScript code on victim machines.
Backdoor that collects the username from the victim.
Gathers information about victim proxy servers.
Backdoor malware that uses mshta.exe to load its components and files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.