Executive Summary
Naid is a Windows backdoor trojan employed by the Elderwood threat group to establish persistent remote control over compromised machines. It typically creates an open TCP channel on port 11002, allowing the attacker to issue shell commands, download new payloads, and exfiltrate data. Timed system disruptions or wiping can be executed as part of a larger multi‑stage operation.
Enhanced Description
Naid is a Windows‑based trojan that acts as a backdoor for its operator group, identified in security research as Elderwood. First surfaced in 2012 by Symantec, Naid installs itself on compromised hosts and opens a persistent remote command and control channel, typically listening on TCP port 11002 or similar opaque ports. The malware supplies the attacker with full administrative privileges: it can spawn command shells, download additional payloads, upload exfiltrated data, and modify registry keys to maintain persistence. Beyond generic backdoor functions, Naid implements several stealth behaviors that increase its survivability. It injects itself into legitimate Windows processes (e.g., svchost.exe) to evade signature‑based detection and uses basic obfuscation techniques for its configuration files and network traffic patterns. When triggered by a remote command, the trojan may also perform file wiping or system lock attempts, thereby disrupting normal operations and potentially augmenting the impact of subsequent credential theft activities. Because Naid was discovered in 2012, many variants exhibit similar C&C infrastructure with command servers distributed via compromised domains. Its integration into the Elderwood ecosystem implies that infected hosts are often subsequently used for lateral movement within corporate networks, exfiltration, or as staging points for ransomware campaigns—underscoring its role in a broader Advanced Persistent Threat framework.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available data about Naid primarily comes from early 2012 Symantec reports. While core capabilities—such as open port backdoor and remote command execution—are well documented, many operational details remain uncertain: specific persistence mechanisms beyond registry edits, encryption schemes used for C&C traffic, and the full range of distributed payload types are not comprehensively described in public sources. Therefore, confidence is moderate; additional analysis of newer samples and internal network telemetry would improve certainty.
Naid is a trojan used by Elderwood to open a backdoor on compromised hosts. (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Naid June 2012)