NKNShell Malware Distributed via VPN Website
ID: 8f35809d-071d-54fb-8b83-3f19a8d15e43
STIX ID: report--8f35809d-071d-54fb-8b83-3f19a8d15e43
Feed Name: ASEC
Threat Score
ASEC confirms an active campaign by Larva-24010 delivering a trojanized Go-based VPN installer which drops PowerShell loaders that install MeshAgent, NKNShell (a Go backdoor using NKN and MQTT for C2), gs-netcat, and SQLMap; the report analyzes the installer behavior, persistence (WMI filters, scheduled tasks), AMSI/ETW bypasses, NKNShell command capabilities and update mechanism, and provides MD5 hashes, URLs, and domains as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
