Executive Summary
Neoichor is a modular command-and-control malware used by the Ke3chang group for persistent, covert operations on Windows systems. It collects system information and exfiltrates data while facilitating lateral movement via WMI and PowerShell. The threat persists through registry run keys or scheduled tasks and relies on encrypted HTTP/HTTPS channels to evade detection.
Enhanced Description
Neoichor is identified as command-and-control (C2) malware that has been in use by the Ke3chang threat actor group since at least 2019, according to Microsoft Security Intelligence reports. It functions as a modular toolkit that communicates with remote servers to download additional payloads and exfiltrate data from infected Windows systems. The malware shares many design elements with related families such as Leeson and Numbldea, suggesting it uses similar persistence mechanisms—including registry run keys and scheduled tasks—to maintain long‑term presence on compromised machines. Operationally, Neoichor gathers detailed system information (hostname, operating system version, user accounts) to map the target environment. It employs Windows Management Instrumentation (WMI) and PowerShell scripts for lateral movement within a network, allowing attackers to pivot from an initial foothold to other systems that may contain higher-value data or credentials. Encrypted command traffic (typically over HTTP/HTTPS) helps obscure its control channel from passive monitoring tools. The primary threat posed by Neoichor is its capacity to remain covert across a large enterprise while harvesting sensitive files and facilitating credential theft. Although public reports have not tied Neoichor directly to wide‑scale breaches, the malware’s architecture indicates it acts as an enabler for deeper compromising operations within victim networks. Further forensic analysis of binary samples would be necessary to confirm whether it incorporates rootkit or kernel‑level persistence techniques. In summary, Neoichor exemplifies a sophisticated, modular C2 platform that empowers Ke3chang with stealthy data collection, persistence, and lateral expansion capabilities throughout Windows environments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate. Available data is limited to intelligence references from Microsoft Security Intelligence; no publicly disclosed binary samples or detailed analysis of Neoichor were accessed during this assessment. Observed capabilities are inferred from related malware families (Leeson, Numbldea), which may not fully represent Neoichor’s behavior.
Neoichor is C2 malware used by Ke3chang since at least 2019; similar malware families used by the group include Leeson and Numbldea.(Citation: Microsoft NICKEL December 2021)