NGLite

S1106

Malware.View on attack.mitre.org

About this malware

NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1016
System Network Configuration Discovery

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.

T1033
System Owner/User Discovery

NGLite will run the whoami command to gather system information and return this to the command and control server.

T1071.001
Web Protocols

NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003.

T1090.003
Multi-hop Proxy

NGLite has abused NKN infrastructure for its C2 communication.

T1573.001
Symmetric Cryptography

NGLite will use an AES encrypted channel for command and control purposes, in one case using the key WHATswrongwithUu.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. NGLite Trojan Open source
    Robert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.