Neoichor is a Windows malware associated with the Ke3chang intrusion set and used in espionage-oriented operations. It functions as a backdoor that performs host profiling and command-and-control communications while incorporating defense-evasion measures. Observed reconnaissance behavior includes collecting the current username, identifying the compromised host’s IP address, and determining the system language. Neoichor also checks for outbound Internet connectivity before proceeding with further activity.
For command-and-control, Neoichor has been observed using the Internet Explorer COM interface to establish communications and receive tasking. It can upload files from compromised systems, indicating an exfiltration role in addition to remote access. The malware also modifies Internet Explorer-related settings in the Windows Registry and can enable automatic clearing of browser history on exit, behavior consistent with operational security and artifact reduction.
Neoichor has been linked to campaigns attributed to Ke3chang, a China-nexus threat actor known for long-running cyber espionage against government, diplomatic, and other strategically relevant organizations. The malware’s observed functionality aligns with post-compromise reconnaissance, remote access, data theft, and defense evasion on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ke3chang ... Examples of associated tools: Okrum, Ketrikan, Neoichor, RoyalDNS, RoyalCli...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Multiple actors and malware check for internet/network connectivity using ping, tracert, HTTP GET requests, or contacting well-known domains (e.g., google[.]com, bing[.]com, 8.8.8.8) prior to tool transfer or C2 establishment.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can collect the username from a victim machine.
Gathers IP addresses from infected hosts.
Malware capable of identifying the system language on a compromised host.
Malware capable of identifying the system language of a compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.