nccTrojan, also referred to as MsmRAT, is a Windows remote access trojan associated with the China-linked espionage group TA428, also tracked as Vicious Panda or BRONZE DUDLEY. It has been observed in Operation LagTime IT and in intrusions targeting government, defense, and aviation-related organizations in East Asia, including Mongolia and Russia. The malware appears to have been under active development, with at least two major branches, commonly described as v1 and v2, that differ substantially in implementation and deployment stage.
nccTrojan provides typical RAT functionality for post-compromise control. Reported capabilities include remote shell access, operating-system command execution, disk and host information collection, file and directory enumeration, file upload and download, file copy and move operations, file and folder deletion, process listing, and process termination. Version 1 used a simpler command-and-control scheme with XOR-obfuscated traffic, while version 2 used a custom TCP protocol with AES-encrypted payloads and an activation mechanism that enabled command handling only after receipt of a specific operator-supplied code.
The malware has been observed primarily as a later-stage payload in TA428 intrusions after internal compromise and lateral movement. In Operation LagTime IT, TA428 used Royal Road-generated lure documents exploiting CVE-2018-0798 to deploy earlier-stage malware such as Poison Ivy and Cotx RAT, followed by credential theft, network reconnaissance, and MS17-010-based lateral movement. After privilege acquisition on internal hosts, nccTrojan v2 was installed as a Windows service by an installer component and executed through a service-hosting process, providing persistence and durable remote access. Separate reporting also indicates that version 1 could be used earlier in the intrusion chain, including in attacks delivered through Royal Road weaponized documents.
nccTrojan is part of a broader TA428 toolset that has included Poison Ivy, Cotx RAT, Tmanger, and Royal Road. Its observed use aligns with long-running Chinese cyber-espionage activity focused on governmental and strategic-sector targets. The malware’s service-based persistence, encrypted command channel, and broad remote administration feature set make it suitable for sustained post-exploitation operations inside compromised Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Used a tool to exploit MS17-010 for lateral movement ... and new RATs such as Tmanger or nccTrojan
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE DUDLEY ... Tools ... NCCTrojan, PhantomNet, PoisonIvy, Royal Road
TA428 was also particularly active, using PoisonIvy, Cotx RAT, Tmanger, and nccTrojan to attack East Asian organizations such as Mongolia.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
"2000" リモートシェルの起動 / "2001", "2002" リモートシェル上でのOSコマンドの実行
v1は単純なXORであるため復号は容易ですが、v2は多少複雑な構造となっています。... DATAフィールドはAESによって暗号化されています。
Poison Ivy C&C Communication ... Tmanger C&C Communication ... nccTrojan C&C Communication
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE DUDLEY threat profile.
TA428が使用するRAT/バックドア。v1とv2の主要バージョンがあり、初期侵入段階でも横展開後でも使われる。ファイル操作、リモートシェル、プロセス操作、ファイル転送、プログラム実行などの機能を備え、v2はサービス登録され独自TCPとAES暗号化通信を用いる。
A trojan used by TA428 in attacks against East Asian organizations.
Previously unreported RAT installed as a fake Windows service and loaded by svchost.exe. It uses AES-CFB-encrypted config/comms and supports remote shell, disk and file listing, process listing, upload/download, file operations, and process killing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.