logo

Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol

ID: 2619c822-9b36-57f3-827b-b9a45897ebf9

STIX ID: report--2619c822-9b36-57f3-827b-b9a45897ebf9

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2023-12-14

Date Updated: 2026-04-29

Author: Kaspersky GERT, GReAT

...
...

NKAbuse is a Go-written, multiplatform Linux implant and botnet backdoor that leverages the NKN peer-to-peer/blockchain network for resilient and anonymous command-and-control. Delivered via exploitation of an Apache Struts2 vulnerability (CVE-2017-5638) against at least one financial organization, the implant supports eight CPU architectures (including amd64, ARM, and MIPS), persists via cron when running as root, offers an extensive set of DDoS flooding payloads plus RAT capabilities (screenshots, command execution, file operations), and Kaspersky telemetry shows victims in Colombia, Mexico, and Vietnam; host IOCs include files under /root/.config/StoreService.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.