Naikon
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:14
- Updated at
- 27/03/2026 01:14
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 24 attack patterns (mitre), 12 malware, 2 sectors, 2 countries, 27 indicators, 7 tool
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (24)
-
Add-ins usesT1137.006 MITRE
-
T1204.002 usesMalicious File MITRE
-
T1078.002 usesDomain Accounts MITRE
-
T1053.005 usesScheduled Task MITRE
-
T1543.003 usesWindows Service MITRE
-
T1003 usesOS Credential Dumping MITRE
-
T1055 usesProcess Injection MITRE
-
T1518.001 usesSecurity Software Discovery MITRE
-
T1134 usesAccess Token Manipulation MITRE
-
T1036.005 usesMatch Legitimate Resource Name or Location MITRE
-
T1056.001 usesKeylogging MITRE
-
T1027 usesObfuscated Files or Information MITRE
Malware (12)
-
HDoor uses
-
Turian - S0647 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RainyDay uses
-
Aria-body uses
-
PlugX - S0013 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
WinMM uses
-
Sys10 uses
-
Nebulae uses
-
RainyDay - S0629 usesFamily
-
RARSTONE uses
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
SslMM uses
Sectors (2)
-
Manufacturing targets
-
Telecommunications targets
Countries (2)
-
Kazakhstan targets
-
Uzbekistan targets
Indicators (27)
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
-
stix 100/100· Valid until 20/09/2026 · Source: AlienVault
Tool (7)
-
Systeminfo usesThe MITRE Corporation Confidence 100
[Systeminfo](https://attack.mitre.org/software/S0096) is a Windows utility that can be used to gather detailed information about a computer. (Citation: TechNet Systeminfo)
-
Ping usesThe MITRE Corporation Confidence 100
[Ping](https://attack.mitre.org/software/S0097) is an operating system utility commonly used to troubleshoot and verify network connections. (Citation: TechNet Ping)
-
ftp usesThe MITRE Corporation Confidence 100
[ftp](https://attack.mitre.org/software/S0095) is a utility commonly available with operating systems to transfer information over the File Transfer Protocol (FTP). Adversaries can use it to transfer other tools onto a…
-
PsExec usesThe MITRE Corporation Confidence 100
[PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.(Citation: Russinovich Sysinternals)(Citation: SANS…
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…
-
Tasklist usesThe MITRE Corporation Confidence 100
The [Tasklist](https://attack.mitre.org/software/S0057) utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It…
-
netsh usesThe MITRE Corporation Confidence 100
[netsh](https://attack.mitre.org/software/S0108) is a scripting utility used to interact with networking components on local or remote systems. (Citation: TechNet Netsh)