Nitol is a Windows malware family best known as a Chinese botnet associated with malware distribution, remote control of infected hosts, and distributed denial-of-service activity. It came to broad attention in 2012 after large-scale abuse of dynamic DNS infrastructure and investigations showing some systems sold in China were already infected through a compromised or counterfeit software supply chain. Nitol has also been linked to counterfeit Windows installations and to preloaded infections on newly purchased PCs.
Nitol functions as a bot client that communicates with command-and-control infrastructure and can receive instructions to conduct DDoS attacks, download and execute additional payloads, update itself, and remove itself. Reported variants also support opening web content through the local browser and destructive actions including overwriting the master boot record, rendering a system unbootable. In more recent observed campaigns, Nitol has been used as a delivery mechanism for other malware, including Amadey, demonstrating continued utility as a malware distribution platform in addition to its botnet role.
Observed Windows variants employ anti-analysis and defense-evasion measures, including packing, virtual machine and sandbox checks, and network-noise generation intended to complicate behavioral analysis. Nitol has also been documented abusing DLL search order hijacking through malicious side-loaded libraries. Persistence has been observed via autorun mechanisms in the current user context. Some reporting also associates Nitol infections with theft of user credentials and passwords, including use in online banking compromise, although capability emphasis across reporting is strongest on botnet control, malware delivery, and DDoS.
Distribution has occurred through multiple channels over time. Historically, infections were tied to compromised supply chains and counterfeit software. More recent campaigns have used fake cracks and keygens distributed through torrent and file-sharing ecosystems, and Nitol has also appeared among malware families delivered by third-party loader services. The malware primarily targets Windows systems and has been discussed alongside overlapping Chinese malware ecosystems and DDoS tooling, including infrastructure or code relationships noted with families such as ServStart and operational overlap in some reporting involving China-based threat activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
This file is being shared via torrent, disguised as cracks for Hancom and MS Office... The malware installed by the threat actor mimic original programs, with names such as TeamViewer, Explorer, and AnyDesk. The threat actor not only disguises the filename but also the icons to resemble the original programs when distributing the malware.
The virtual environment check uses the IN command to check whether it is running on a VMware virtual machine. As for sandbox environments, it checks whether the “api_log.dll” and “SbieDll.dll” DLLs are loaded. If it confirms that it’s in a virtual or sandbox environment, Nitol is shut down.
Currently, access to the C&C server is unavailable, but once the connection is successfully established, the malware transmits basic information about the infected system... Language and country information, Computer name, Windows version, RAM size, CPU performance.
The virtual environment check uses the IN command to check whether it is running on a VMware virtual machine. As for sandbox environments, it checks whether the “api_log.dll” and “SbieDll.dll” DLLs are loaded. If it confirms that it’s in a virtual or sandbox environment, Nitol is shut down.
When the installation process is complete, it executes the malware in the copied path and connects to the C&C server... When Nitol sends the infected system’s information to the C&C server, the server returns the command.
Nitol supports a command that downloads additional payloads, and this command was used to install Amadey Bot... Amadey shows that it receives a command from the C&C server to install additional payloads, and accordingly, it downloads and installs a total of 4 files.
The 3322.org domain is a Dynamic DNS which was used by the botnet creators as a command and control infrastructure for controlling their botnet.
"Microsoft’s takedown of 3322.org to disrupt the Nitol botnet is partial (3322 is not the only dynamic DNS provider Nitol uses)..." and "...had a massive infestation of cybercriminals creating and cycling through thousands of hostnames for botnet command and control..."
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that can function as a DDoS bot and install Amadey; mentioned in relation to malicious binaries communicating with loomfi[.]com.
A malware family observed as one of the payloads distributed by PrivateLoader.
Botnet malware referenced as associated with process injection activity in the provided content.
Nitol is described as a DDoS bot used in ongoing attacks, distributed via torrent and fake crack/keygen lures. It supports multiple DDoS attack modes, anti-analysis checks, persistence via the Run key, payload download and execution, hidden or visible Internet Explorer page access, update capability, and an MBR-destruction command that renders systems unbootable after reboot. In this campaign it was used to download and install Amadey.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.