logo

NAPLISTENER: more bad dreams from developers of SIESTAGRAPH

ID: 04e301a7-98f0-5c0b-9b63-ff6efc5be1b7

STIX ID: report--04e301a7-98f0-5c0b-9b63-ff6efc5be1b7

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-06-27

Date Updated: 2026-04-27

...
...

### Executive summary Elastic Security Labs analyzed NAPLISTENER, a C# HTTP-listener backdoor deployed as Wmdtc.exe that masquerades as Msdtc.exe to persist as a Windows service. The implant accepts base64-encoded .NET assemblies via a web path (/ews/MsExgHealthCheckd/) and executes them in memory, intentionally bypassing IIS logs and network-based detection; the report includes analysis of behavior, setup prerequisites (SSL cert binding), a YARA detection rule, and links to similar public code that likely influenced the implant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.