Neurevt is a trojan/backdoor malware family with spyware, credential-theft, and remote access capabilities. The provided content describes a June 2021 variant reported by Cisco Talos that appeared to target users of Mexican financial institutions. Talos observed infection beginning with an obfuscated PowerShell command, likely launched from a Microsoft Office document or JavaScript, which bypassed execution policy and downloaded a first-stage executable from saltoune[.]xyz/pb/aa.exe. Subsequent stages dropped VBS and batch scripts, unpacked additional payloads, performed process injection, deleted artifacts, and copied the malware to C:\ProgramData\Google Updater 2.09\13q77qiq.exe and temporary locations.
Capabilities directly described in the content include spyware and backdoor behavior, theft of credentials and 2FA-related data from Mexican banking websites, keylogging, mouse/input capture, screenshot and clipboard collection, host information gathering, persistence via Image File Execution Options and Run/RunOnce registry keys, and exfiltration over HTTP POST using .NET System.Web classes. Defense evasion and anti-analysis behaviors included deleting Mark-of-the-Web zone identifiers, disabling the Windows firewall via registry changes, weakening Internet Explorer/ZoneMap settings, and checking for VirtualBox/VMware artifacts and debugger-related conditions. The malware also attempted privilege escalation by stealing service token information and manipulating token privileges.
Command-and-control and payload infrastructure mentioned in the content includes saltoune[.]xyz, russk17[.]icu, russk18[.]icu, russk19[.]icu, russk20[.]icu, russk21[.]icu, russk22[.]icu, moscow11[.]at, moscow13[.]at, and morningstarlincoln[.]co[.]uk. A historical reference in the content also lists abcnyx98cz.de as a Neurevt C&C domain from 2015. File indicators explicitly provided include SHA-256 86aab09b278fe8e538d8cecd28f2d7a32fe413724d5ee52e2815a3267a988595 for the stage-1 executable, 5624eea08b241314b8bd13ee9429449c53085a6bb2bcc481655f1f28b4314122 for 13q77qiq.exe, 35617cfc3e8cf02b91d59209fc1cd07c9c1bc4d639309d9ab0198cd60af05d29 for a downloaded PE from morningstarlincoln[.]co[.]uk, and 4d3ee3c1f78754eb21b3b561873fab320b89df650bbb6a69e288175ec286a68f for seer.exe from russk17[.]icu.
The content does not provide a definitive threat-actor attribution for Neurevt. It does note that infrastructure such as russk22[.]icu and related domains has been observed across other malware campaigns in Latin America, suggesting possible infrastructure sharing or reuse, but this is not sufficient to attribute Neurevt itself to a specific actor with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
The loader will unpack the payload and inject it into its own child process... In most cases, the main payload will first be injected into a second instance of Explorer.exe. However, in one of the incidents, we observed Betabot injecting itself into a McAfee process called “shtat.exe”.
Betabot’s main features include... Robust Userland Rootkit (x86/x64)... Once Betabot is executed, it make extensive usage of API hooking to hide the persistence from regedit, Sysinternal’s Autoruns and other monitoring tools.
The Betabot infections seen in our telemetry originated from phishing campaigns that used social engineering to persuade users to download and open what appears to be a Word document... Examining the document in a Hex editor, we can see that it is, in fact, an RTF file.
The loader will unpack the payload and inject it into its own child process... In most cases, the main payload will first be injected into a second instance of Explorer.exe. However, in one of the incidents, we observed Betabot injecting itself into a McAfee process called “shtat.exe”.
Delete traces of the original RTF document by enumerating all the Resiliency registry keys and deleting them... hondi.cmd Deleting traces by deleting the resiliency registry entry
Betabot will attempt to determine if it is executed in a virtual environment by querying the registry and looking for the names of virtual machine vendors such as VMware, VirtualBox and Parallels... Another trick used to determine if the environment is virtual is to obtain a handle to \\Device\\Harddisk0\\Partition and \\??\\PHYSICALDRIVE0.
Betabot will attempt to determine if it is executed in a virtual environment by querying the registry and looking for the names of virtual machine vendors such as VMware, VirtualBox and Parallels... Another trick used to determine if the environment is virtual is to obtain a handle to \\Device\\Harddisk0\\Partition and \\??\\PHYSICALDRIVE0.
Once injected, Betabot will attempt to communicate with its C2 servers... Once Internet connectivity is verified, Betabot will send requests to its C2 servers.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage Windows trojan targeting online banking users (notably Mexican financial institutions). Delivered via obfuscated PowerShell (likely from Office/JS), establishes persistence via registry (Run/RunOnce and Image File Execution Options), performs process injection, keylogging and mouse input monitoring via hooks, screenshot and clipboard capture, system discovery, privilege manipulation via token APIs, defense evasion (removes Mark-of-the-Web, disables firewall, weakens IE zone settings), VM/debugger detection, and exfiltrates data over HTTP POST to C2 infrastructure using .NET System.Web classes.
Backdoor malware associated with botnet controllers.
Neurevt is referenced as using a command-and-control domain, indicating botnet malware infrastructure.
Malware family referenced as part of campaigns leveraging overlapping/shared infrastructure domains in the region.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.