DarkNimbus is a cross-platform backdoor used in China-aligned espionage activity and associated most prominently with the Earth Minotaur cluster. It has Android and Windows variants and has been under active development since at least 2018. The malware has been delivered through the MOONSHINE exploit kit and through adversary-in-the-middle traffic hijacking operations conducted from compromised routers and edge devices by the DKnife framework. It has also been reported in activity linked to TheWizards.
On Android, DarkNimbus is deployed after exploitation of vulnerable Chromium-based browser components and Tencent Browser Server implementations embedded in applications, including WeChat. In observed MOONSHINE chains, exploitation replaced the browser engine package with a trojanized component containing the backdoor. The Android implant supports extensive surveillance and collection, including device profiling, installed application enumeration, contacts, SMS, call history, GPS data, clipboard contents, browser bookmarks, files, screenshots, photos, and audio recordings. It also abuses Android Accessibility Service to capture conversations from foreground messaging applications. Broader code support has been observed for collection from multiple chat platforms, while some delivered variants were configured specifically for WeChat-focused theft.
On Windows, DarkNimbus is a C++ backdoor that supports host profiling, installed software enumeration, file collection, browsing-history theft, screenshot capture, keystroke logging, clipboard theft, shell command execution, and browser credential theft. In some delivery chains it is loaded after a ShadowPad infection stage, including via DLL sideloading. DKnife has also been observed hijacking Windows software downloads and Android application updates to deliver DarkNimbus to downstream victims behind compromised gateways.
DarkNimbus uses XMPP through the Smack library for command-and-control on Android and HTTPS for file transfer. Reporting also indicates infrastructure-assisted command-and-control redirection in some campaigns, where gateway malware intercepts requests and reroutes the implant to operational servers. Targeting associated with DarkNimbus activity has included Tibetan and Uyghur communities, Chinese-speaking users, and victims reached through compromised network infrastructure or malicious links distributed over instant messaging platforms. The malware is best characterized as a surveillance-oriented backdoor supporting credential theft, data exfiltration, and remote post-compromise control across mobile and Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Vulnerability Targeted Version CVE-2016-1646 Chrome 39~49
CVE-2020-6418 is the only newer vulnerability included in the version of MOONSHINE exploit kit we observed.
Vulnerability Targeted Version CVE-2018-17480 Chrome 70~73, TBS 44605
Vulnerability Targeted Version CVE-2018-6065 Chrome 62~63
Vulnerability Targeted Version CVE-2018-17463 Chrome 68~69
Vulnerability Targeted Version CVE-2016-5198 Chrome 50
Cisco Talos Intelligence Group recently published details on CVE-2023-3420 vulnerability that targets WeChat. We believe the related exploit is part of the MOONSHINE framework.
Vulnerability Targeted Version CVE-2017-5070 Chrome 56~58
Vulnerability Targeted Version CVE-2017-5030 Chrome 51~55
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TheWizard also used the DarkNimbus backdoor which was developed by the Earth Minotaur threat actor.
TheWizard also used the DarkNimbus backdoor which was developed by the Earth Minotaur threat actor.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious links led victims to MOONSHINE exploit kit servers, which install backdoors on the victims’ devices.
“DKnife hijacks software downloads and Android app updates to spread ShadowPad and DarkNimbus backdoors.”
MOONSHINE uses multiple Chromium exploits to attack instant messaging apps on Android... This gives attackers a great opportunity to exploit these vulnerabilities and install their backdoors.
For the Android variants, the backdoor attempts to contact a Baidu URL "http[:]//fanyi.baidu[.]com/query_config_dk" to retrieve its C2 information. This URL does not return any response from Baidu itself; rather, it serves as a recognizable trigger for DKnife, which intercepts the request and injects the C2 response.
For the Android variants, the backdoor attempts to contact a Baidu URL "http[:]//fanyi.baidu[.]com/query_config_dk" to retrieve its C2 information. This URL does not return any response from Baidu itself; rather, it serves as a recognizable trigger for DKnife, which intercepts the request and injects the C2 response.
cmd_10001 Collect mobile device information... / cmd_10001 Collect host information: OS, computername, username, cpu, memory size...
DarkNimbus uses the XMPP protocol to communicate with a C&C server... In addition, it communicates to another server via HTTPS; this server is used mainly for file transfers.
Downloads the trojanized XWalk APK from the remote server... / Downloading the “libwcdb.so” file from a remote server for the backdoor to use
For the Android variants, the backdoor attempts to contact a Baidu URL "http[:]//fanyi.baidu[.]com/query_config_dk" to retrieve its C2 information. This URL does not return any response from Baidu itself; rather, it serves as a recognizable trigger for DKnife, which intercepts the request and injects the C2 response.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned only as background in relation to TheWizard and Earth Minotaur.
Cross-platform (Android and Windows) backdoor used for long-term surveillance, delivered via MOONSHINE exploit kit.
Backdoor associated with the Earth Minotaur cluster and also referenced as used by the APT group TheWizards; delivered via DKnife-facilitated traffic manipulation.
Backdoor delivered by the DKnife toolkit in this campaign; specific capabilities not described in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.