Researchers linked a sustained cyber-espionage campaign against military, government, and intelligence organizations in Southeast Asia to the Chinese-speaking Naikon threat actor, which used the FoundCore/RainyDay backdoor alongside a newly documented Nebulae implant. Bitdefender said Nebulae was typically delivered through DLL side-loading with legitimate software and used mainly for persistence and as a fallback access path after defenders detected other malware, while FoundCore handled reconnaissance, credential dumping, lateral movement, payload delivery, and ongoing remote access.
Technical reporting shows the intrusions relied on multi-stage loaders, obfuscated shellcode, and hijacked legitimate components to evade analysis and maintain access. Securelist documented related tradecraft in attacks on high-profile Vietnamese organizations, including side-loading through Microsoft Outlook components, RC4-encrypted communications, runtime repair of scrubbed PE headers, and service-based persistence, while separate Kaspersky research tied Naikon to the long-running Aria-Body backdoor family used against executive, law enforcement, military, and intelligence entities across the South China Sea region. The combined reporting indicates Naikon continued refining a long-running regional espionage toolkit rather than conducting isolated intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Bitdefender said the observed Naikon attacks using Nebulae and RainyDay/FoundCore ran through March 2021, relying on side-loading and DLL hijacking through legitimate applications.
Securelist listed a CoreLoader sample associated with the campaign with a creation time of 2020-11-21 03:47:14, indicating another malware stage used in the intrusion chain.
A DropPhone implant used in the intrusion chain had a recorded creation time of 2020-11-04 09:14:22 and was deployed after RoyalRoad-generated RTF exploitation.
Securelist reported a multi-stage intrusion campaign active from June 2020 to January 2021 that primarily targeted high-profile Vietnamese organizations and deployed the FoundCore RAT via DLL side-loading.
Bitdefender observed Naikon conducting cyber-espionage operations against military organizations in Southeast Asia, using the FoundCore/RainyDay backdoor and the Nebulae backdoor for persistence and backup access.
A newer AR sample compiled on 2018-02-22 added raw input device-based keylogging functionality, which Kaspersky said was absent from previous versions of the malware.
Kaspersky reported that Naikon continued cyber-espionage campaigns in Southeast Asia and the South China Sea region during 2018, targeting government, military, intelligence, and related organizations.
Kaspersky identified at least six AR/Aria-Body backdoor variants with compilation dates spanning from January 2017 to February 2018, used in cyber-espionage targeting Southeast Asian organizations.
Kaspersky reported that portions of Naikon's AR/Aria-Body codebase could be traced back to executable and DLL modules used in the group's operations since 2012, indicating long-term malware lineage continuity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.