Netero is a custom backdoor associated with the xHunt intrusion set, a Kuwait-focused cyber-espionage actor active since at least 2018. It belongs to a broader malware ecosystem whose components are named after characters from the anime Hunter x Hunter, including Hisoka, Sakabota, Killua, Gon, and EYE. Netero has been referenced as a distinct tool created after functionality was removed from Hisoka, indicating shared development lineage within the same bespoke toolset.
The malware has been used in operations targeting organizations in Kuwait, particularly in the transportation and shipping sectors, as part of long-term intelligence collection activity. xHunt operations have also targeted government entities and have relied on compromised Microsoft Exchange and IIS infrastructure, credential harvesting, and covert command-and-control methods. Within this operational context, Netero is described as one of the backdoors deployed to maintain access and support espionage objectives.
The broader xHunt toolkit demonstrates an emphasis on persistence, covert command and control, credential abuse, and post-compromise maneuvering inside victim environments. Related implants in the same family have used HTTP, DNS tunneling, and Exchange Web Services draft-based communications, and have been paired with auxiliary tooling for reconnaissance, remote command execution, lateral movement, and cleanup. Netero is best understood as part of this custom backdoor framework used to infiltrate critical organizations and harvest sensitive information, although specific technical details about its standalone functionality are currently not available at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom backdoor deployed by xHunt APT to maintain long-term access and facilitate cyber-espionage operations.
Named xHunt backdoor/tool referenced as part of the group's custom toolkit; specific functionality not described in the provided content.
Modular component embedded inside Hisoka v0.9 as a resource and dropped when needed, indicating the developer was separating functionality from Hisoka into another tool to improve modularity and evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.