nccTrojan, also known as MsmRAT, is a Windows remote access trojan associated with the China-linked TA428 threat group and Operation LagTime IT. It has been used against East Asian government entities and against defense- and aviation-related organizations in Russia and Mongolia. At least two substantially different branches, v1 and v2, have been identified. Version 1 has appeared during initial intrusion activity, including infections initiated through Royal Road-generated RTF lure documents exploiting Microsoft Office Equation Editor vulnerabilities. Version 2 is generally deployed after lateral movement and elevated access, and establishes persistence as a Windows service. nccTrojan provides remote shell and operating-system command execution, disk and file enumeration, process listing and termination, program execution, file and directory operations, and bidirectional file transfer. Version 1 uses XOR-obfuscated command-and-control traffic, while version 2 uses a custom TCP protocol with AES-encrypted payloads and requires a configured activation value before processing backdoor commands. The malware remained under active development and use across both major branches.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit MS17-010 for lateral movement, NETBIOS scanner for environmental investigations, tools to steal credentials and new RATs such as Tmanger or nccTrojan.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
'WindowsResKits.dll' is a new type of malware that we call nccTrojan.
BRONZE DUDLEY ... Tools ... NCCTrojan, PhantomNet, PoisonIvy, Royal Road
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Tmanger has following functions: Remote Shell (cmd.exe); Remote Shell (powershell.exe)... nccTrojan has following functions: Remote Shell.
v1は単純なXORであるため復号は容易ですが、v2は多少複雑な構造となっています。... DATAフィールドはAESによって暗号化されています。
Configuration data lists C&C servers on ports 443, 8080, 80, and 5222; sections describe C&C communication for Poison Ivy, Tmanger, and nccTrojan.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE DUDLEY threat profile.
TA428が使用するRAT/バックドア。v1とv2の主要バージョンがあり、初期侵入段階でも横展開後でも使われる。ファイル操作、リモートシェル、プロセス操作、ファイル転送、プログラム実行などの機能を備え、v2はサービス登録され独自TCPとAES暗号化通信を用いる。
A trojan used by TA428 in attacks against East Asian organizations.
Previously unknown RAT installed as a fake Windows service and loaded by svchost.exe. It uses AES-CFB-encrypted configuration and communications and supports remote shell, disk and file listing, process listing, file upload/download, file operations, and process killing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.