Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Neoichor

Neoichor

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Neoichor is a modular command-and-control malware used by the Ke3chang group for persistent, covert operations on Windows systems. It collects system information and exfiltrates data while facilitating lateral movement via WMI and PowerShell. The threat persists through registry run keys or scheduled tasks and relies on encrypted HTTP/HTTPS channels to evade detection.

Enhanced Description

Neoichor is identified as command-and-control (C2) malware that has been in use by the Ke3chang threat actor group since at least 2019, according to Microsoft Security Intelligence reports. It functions as a modular toolkit that communicates with remote servers to download additional payloads and exfiltrate data from infected Windows systems. The malware shares many design elements with related families such as Leeson and Numbldea, suggesting it uses similar persistence mechanisms—including registry run keys and scheduled tasks—to maintain long‑term presence on compromised machines. Operationally, Neoichor gathers detailed system information (hostname, operating system version, user accounts) to map the target environment. It employs Windows Management Instrumentation (WMI) and PowerShell scripts for lateral movement within a network, allowing attackers to pivot from an initial foothold to other systems that may contain higher-value data or credentials. Encrypted command traffic (typically over HTTP/HTTPS) helps obscure its control channel from passive monitoring tools. The primary threat posed by Neoichor is its capacity to remain covert across a large enterprise while harvesting sensitive files and facilitating credential theft. Although public reports have not tied Neoichor directly to wide‑scale breaches, the malware’s architecture indicates it acts as an enabler for deeper compromising operations within victim networks. Further forensic analysis of binary samples would be necessary to confirm whether it incorporates rootkit or kernel‑level persistence techniques. In summary, Neoichor exemplifies a sophisticated, modular C2 platform that empowers Ke3chang with stealthy data collection, persistence, and lateral expansion capabilities throughout Windows environments.

Key Capabilities

  • Establishes command-and-control over encrypted HTTP/HTTPS channels
  • Downloads and executes additional modular payloads
  • Collects system information for host profiling
  • Persists via registry run keys and scheduled tasks
  • Exfiltrates sensitive files and data
  • Uses PowerShell and WMI for lateral movement

ATT&CK Techniques

T1071.001
T1059
T1086
T1040
T1064
T1055.002

Recommended Actions

  • Implement network segmentation to limit lateral spread from compromised hosts
  • Deploy IDS/IPS signatures targeting Neoichor command traffic patterns
  • Enable EDR with focus on anomalous WMI and PowerShell executions
  • Monitor registry run key changes and enforce strict application whitelisting
  • Block known C2 IP addresses, domains, and TLS cert fingerprints

Suggested Tags

Neoichor
Ke3chang
MalwareFamily
C2
Windows
Persistence
LateralMovement

Confidence Assessment

Moderate. Available data is limited to intelligence references from Microsoft Security Intelligence; no publicly disclosed binary samples or detailed analysis of Neoichor were accessed during this assessment. Observed capabilities are inferred from related malware families (Leeson, Numbldea), which may not fully represent Neoichor’s behavior.

Description

Neoichor is C2 malware used by Ke3chang since at least 2019; similar malware families used by the group include Leeson and Numbldea.(Citation: Microsoft NICKEL December 2021)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.