logo

NKabuse backdoor harnesses blockchain brawn to hit several architectures

ID: 80a36cf8-197e-5f3c-8bfd-ff799a19d83f

STIX ID: report--80a36cf8-197e-5f3c-8bfd-ff799a19d83f

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2023-12-15

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A Go-based multi-platform backdoor called "NKAbuse" was found using the New Kind of Network (NKN) P2P/blockchain protocol for anonymized C2. NKAbuse exploits a public PoC for Apache Struts 2 (CVE-2017-5638) to install architecture-specific payloads (eight architectures, prioritizing Linux), achieves persistence via cron, supports RAT functions (remote command execution, file listing, screenshots) and 12 DDoS attack types, and has been observed in victims in Mexico, Colombia, and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.