Nerex

S0210

Malware.View on attack.mitre.org

About this malware

Nerex is a Trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1105
Ingress Tool Transfer

Nerex creates a backdoor through which remote attackers can download files onto a compromised host.

T1112
Modify Registry

Nerex creates a Registry subkey that registers a new service.

T1543.003
Windows Service

Nerex creates a Registry subkey that registers a new service.

T1553.002
Code Signing

Nerex drops a signed Microsoft DLL to disk.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Nerex May 2012 Open source
    Ladley, F. (2012, May 15). Backdoor.Nerex. Retrieved February 23, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.