A targeted spear-phishing operation used convincing decoy documents to compromise entities in Taiwan and the Vietnamese government, delivering the Agent.NJK backdoor and Terminator RAT. The attackers relied on social engineering rather than software exploits, disguising malware with Word document icons and hidden executable extensions so victims would launch the payloads themselves. Researchers found that Agent.NJK functioned as a simple HTTP backdoor and trojan proxy with hard-coded command-and-control infrastructure and signs of live operator activity, including reconnaissance commands and an apparent typo consistent with manual control.
Terminator RAT was described as more feature-rich but poorly engineered, using an XTEA-encrypted configuration, a custom XOR/ROR network protocol, persistence through Startup Folder manipulation and delayed file moves, and a separate proxy tunnel component to move data through corporate proxies. The activity was linked to earlier reporting through reused tooling, dynamic DNS infrastructure, and command-and-control servers in the same Taiwan-based /24 network, indicating an ongoing intrusion set marked by targeted victim selection but weak malware development, bad cryptography, and operational mistakes.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
After interacting with the monitored infection, the Agent.NJK command-and-control server stopped engaging and sent TCP resets on all configured ports. The report says this occurred after the operators determined the host was not of interest.
During analysis, researchers observed manual interaction with an Agent.NJK-infected host, including reconnaissance commands such as drive enumeration, netstat, environment queries, and directory listings. A mistyped command, "netsta -ano," indicated hands-on-keyboard operation rather than full automation.
A targeted campaign used spear-phishing emails with decoy document executables to infect entities in Taiwan and the Vietnamese government. The operation relied on social engineering rather than software exploits and delivered Agent.NJK and Terminator RAT via a reusable dropper.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.