A sophisticated cyberespionage campaign known as PassiveNeuron has been actively targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. The campaign was initially discovered in June 2024, when researchers identified a series of attacks involving previously unknown advanced persistent threat (APT) implants named Neursite and NeuralExecutor. Neursite is a modular C++ backdoor, while NeuralExecutor is an implant designed to execute additional .NET payloads, both of which had not been observed in other threat campaigns prior to this discovery. After a period of inactivity, a new wave of infections linked to PassiveNeuron was detected between December 2024 and August 2025, indicating the campaign's persistence and adaptability. The attackers primarily targeted Windows Server machines, with a particular focus on those running Microsoft SQL Server software. In at least one documented case, the attackers achieved initial remote command execution on a compromised server through the SQL software, although the exact method of exploitation remains unclear. Potential attack vectors include exploitation of vulnerabilities in the SQL server software, SQL injection flaws in applications, or brute-forcing database administrator credentials. Once initial access was established, the attackers deployed the custom Neursite and NeuralExecutor implants to maintain persistence and facilitate further malicious activity. Additionally, Cobalt Strike, a legitimate red teaming tool often abused by threat actors, was used as a payload to enhance lateral movement and post-exploitation capabilities. The campaign's focus on servers exposed to the internet underscores the strategic value these assets hold for APT groups seeking to infiltrate high-value targets. Attribution remains uncertain, but the use of sophisticated, custom malware and the selection of high-profile targets suggest a well-resourced and highly skilled threat actor. The campaign's operational security and the novelty of its implants have made detection and analysis challenging for defenders. Researchers have been able to prevent further spread in some cases, but the ongoing nature of the campaign highlights the need for heightened vigilance among organizations operating critical infrastructure. The technical sophistication of PassiveNeuron, combined with its global reach and focus on sensitive sectors, marks it as a significant threat in the current cyber threat landscape. Organizations are advised to review their SQL server security, monitor for unusual activity, and ensure robust credential management to mitigate the risk of compromise. The campaign demonstrates the evolving tactics of APT actors and the importance of timely threat intelligence sharing among defenders.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On October 21, 2025, Kaspersky published new research on PassiveNeuron, detailing the Neursite and NeuralExecutor implants and the campaign's targeting of Windows Server systems. The company said attribution remained uncertain but noted GitHub dead-drop C2 patterns and other TTPs resembling Chinese-speaking threat actors, as well as overlap with a DLL path previously referenced by Cisco Talos in reporting tied to suspected APT41 activity.
Kaspersky said the renewed PassiveNeuron activity continued from December 2024 through at least August 2025. The sustained campaign affected organizations in multiple regions and sectors, showing that the operation remained active for months after the 2024 disruption.
When web shell deployment failed, the operators used a multi-stage DLL loader chain with Phantom DLL Hijacking, oversized DLLs, MAC-address victim checks, and staged decryption. This chain ultimately loaded the Neursite backdoor, the NeuralExecutor .NET implant, or Cobalt Strike on victim systems.
In at least one observed intrusion during the renewed campaign, the attackers achieved initial remote code execution through Microsoft SQL Server. They then repeatedly attempted to deploy an ASPX web shell using encoded payloads and scripting, though those attempts were blocked.
From December 2024, Kaspersky observed a renewed wave of PassiveNeuron infections targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. The campaign primarily focused on machines running Windows Server.
Kaspersky observed an apparent lull in PassiveNeuron activity after a disruption in June 2024. The pause marked a temporary break in the campaign before operators resumed infections later that year.
Kaspersky first reported the targeted cyberespionage campaign known as PassiveNeuron in 2024, identifying it as an operation compromising government-organization servers. This established the campaign as an ongoing intrusion set before later technical details were published.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcesecurelist.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.