NAPLISTENER is a C# HTTP-listener backdoor associated with the REF2924 espionage intrusion set. It is deployed as a Windows service under a name intended to resemble a legitimate Microsoft service component. The implant receives specially formatted inbound HTTP requests, Base64-decodes an attacker-supplied .NET assembly, and loads and executes the assembly directly in memory. It operates separately from IIS and handles matching requests through Windows HTTP request redirection, reducing visibility in IIS web-server logs and hindering detection based on web logs or network inspection. Its HTTP response behavior and server-like headers are intended to blend with expected web traffic. NAPLISTENER requires endpoint SSL and application-registration configuration to operate. REF2924 activity involving NAPLISTENER has been concentrated in southern and southeastern Asia and is associated with persistent access operations against government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NAPLISTENER is an HTTP listener written in C#... creates an HTTP request listener that can process incoming requests from the internet, reads any data that was submitted, decodes it from Base64 format, and executes it in memory.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
“When a request comes in, it reads any data that was submitted (stored in a Form field), decodes it from Base64 format, and creates a new HttpRequest object with the decoded data.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named implant/tool previously observed in the REF2924 intrusion set.
Previously observed malware in the same government victim environment; no functionality is described here.
A C# persistent-access implant installed as a Windows service. It listens on an HTTP endpoint, filters command traffic from legitimate web requests, Base64-decodes a submitted .NET assembly, and loads and executes that assembly in memory. It imitates web-server behavior to evade network and log-based monitoring.
Referenced as a previously analyzed malware family and deployment technique, without technical functionality in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.