The Wild Neutron threat actor, also tracked as Jripbot and Morpho, was reported to have continued a long-running espionage campaign that began by at least 2011 and evolved from broad watering-hole compromises into more selective intrusions. Earlier operations reportedly hit high-profile technology targets including Apple, Facebook, Twitter, and Microsoft, while later activity focused on law firms, Bitcoin-related businesses, investment firms, IT providers, healthcare organizations, real estate companies, and specific individuals.
Researchers said the group used an unknown Adobe Flash Player exploit in 2015 and deployed a modular toolset built around the Jripbot backdoor, alongside SSH-based exfiltration utilities and a dropper signed with a stolen Acer code-signing certificate. The campaign’s tradecraft included encrypted command-and-control traffic, anti-sandbox techniques, reuse of open-source and leaked malware code, Unix-style tools ported through Cygwin, and victim-specific fallback domain resolution, leading investigators to assess the operation as a sophisticated campaign driven primarily by economic espionage.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
The Securelist report stated that Wild Neutron was still active as of June 2015, continuing to use modular malware centered on the Jripbot backdoor and related tooling.
In 2015, Kaspersky observed exploitation chains involving cryptomag.mediasource[.]ch and find.a-job.today, with evidence indicating use of an unknown Flash Player exploit.
In 2014–2015, Wild Neutron targeted law firms, Bitcoin-related companies, investment firms, large corporate groups involved in M&A, IT companies, healthcare companies, real estate companies, and individual users.
Kaspersky said the actor resumed operations in late 2013 and early 2014, beginning a new phase of targeted intrusions that continued into 2015.
During the 2013 campaign, the group compromised iphonedevsdk[.]com and fedoraforum[.]org, and also targeted other forums including expatforum.com, mygsmindia.com, forum.samdroid.net, emiratesmac.com, forums.kyngdvb.com, community.flexispy.com, and ansar1.info.
In 2013, Wild Neutron compromised high-profile companies including Apple, Facebook, Twitter, and Microsoft through watering-hole attacks using a Java zero-day detected as Exploit.Java.CVE-2012-3213.b.
Kaspersky reported that the Wild Neutron espionage actor, also known as Jripbot and Morpho, had been active since at least 2011.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.