NFlog is a Windows remote access trojan associated with espionage activity attributed to DragonOK and later reported in operations linked to SAMURAI PANDA; related reporting also describes IsSpace as a newer variant or evolution of NFlog. It has been used as a follow-on backdoor in targeted intrusions against organizations including Japanese manufacturing and high-technology entities, and has also appeared in watering-hole and exploit-driven delivery chains.
NFlog provides standard RAT functionality and maintains command-and-control communications over HTTP, polling its infrastructure at short intervals for tasking. Reported capabilities include remote command execution, file upload and download, host profiling, and exfiltration of victim information. The malware is proxy-aware and has been observed attempting to obtain or enumerate proxy authentication credentials, including behavior consistent with sniffing or harvesting proxy credentials on some systems. It also performs connectivity checks and uses mutex or event objects to ensure a single running instance.
On Windows systems, NFlog has been observed establishing persistence through autorun mechanisms in the current user context. It has also been reported to attempt privilege escalation or elevated relaunch on newer Windows versions using a CryptBase.dll side-loading technique involving sysprep, functioning as a UAC-bypass style method. Related IsSpace samples retained overlapping command structure and encryption patterns, including XOR-obfuscated network data and similar command-and-control URI conventions, supporting the assessment that IsSpace is closely related to or descended from NFlog.
Delivery observed for NFlog or its IsSpace-related variants includes phishing campaigns and watering-hole attacks leveraging a repurposed Adobe Flash exploit for CVE-2015-5122. In DragonOK operations, NFlog was one of several backdoors staged after initial compromise by first-stage malware. Overall, NFlog is best characterized as a straightforward but operationally useful espionage RAT used in targeted campaigns against organizations of strategic interest.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The following report details a new variant of the NfLog Remote Access Tool (RAT), also known as IsSpace, used by SAMURAI PANDA. This new variant is deployed using a repurposed version of the leaked Hacking Team Adobe Flash Exploit which leverages CVE-2015-5122. | The following report details a new variant of the NfLog Remote Access Tool (RAT), also known as IsSpace, used by SAMURAI PANDA.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Three of the backdoors, NFlog, PoisonIvy, and NewCT have previously been publicly associated with DragonOK.
Based on its codebase and behavioral patterns, it appears that IsSpace could possibly be an evolution of the NFlog backdoor, which has previously been attributed to the adversary groups DragonOK and Moafee.
The following report details a new variant of the NfLog Remote Access Tool (RAT), also known as IsSpace, used by SAMURAI PANDA.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence is achieved through the setting of an ASEP after the RAT has been installed to a particular folder.
The POST data sent in this request is encrypted using the same four-byte XOR key of '\x35\x8E\x9D\x7A' that has been used by the NFlog tool.
The primary C2 server communicates over port 80. Alternate ports are configurable through the secondary C2 server variable.
Sysget communicates with this server using the HTTP protocol... FormerFirstRAT communicates using unencrypted HTTP over port 443... All data is sent via HTTP POST requests.
This new variant also incorporates the use of the Google App Engine (GAE) hosting to proxy communications to its C2 Server.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior DragonOK backdoor family referenced as the predecessor to IsSpace; mentioned for lineage and shared protocol/keying context rather than as the main malware analyzed here.
A backdoor malware family referenced as the likely predecessor of IsSpace. The content notes shared code, behavior, XOR-encrypted communications, Windows XP connectivity checks, and similar victim-information exfiltration patterns.
A backdoor DLL that persists via a Run registry key, uses XOR-obfuscated strings, creates a named event to enforce single instance execution, and performs network connectivity checks before malicious activity.
A DLL backdoor that spawns a malicious thread, persists via a Run key, uses XOR string obfuscation, creates a named event for single-instance control, attempts local port binding, and checks Internet connectivity via HTTP requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.