Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware NOKKI

NOKKI

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

NOKKI is a modular Windows RAT first seen in early 2018, sharing code with the Konni family and likely employed by APT37. It provides persistent remote control, credential theft, and covert exfiltration via legitimate protocols, complicating detection. The malware’s plugin architecture allows attackers to expand capabilities dynamically.

Enhanced Description

NOKKI is a modular, Windows‑based remote access trojan that first surfaced in January 2018. The code base demonstrates significant overlap with the Konni family, suggesting shared development lineage or common authorship. Analysts have linked NOKKI to APT37 operations, and it has been discussed extensively by Unit 42 in their 2018 reports. Like its Konni counterpart, NOKKI is engineered for stealth and persistence. The toolkit includes a plug‑in architecture that allows operators to inject additional modules at runtime—enabling functionalities such as keylogging, credential dumping, remote file management, and lateral movement. Persistence mechanisms typically involve registry service creations or scheduled tasks, while clean‑up routines may remove registry entries upon disconnection. The RAT’s modularity also permits exfiltration over legitimate protocols, usually HTTP(S) or DNS tunneling, obfuscating traffic from baseline anomaly detection systems. When combined with APT37 activity, NOKKI is implicated in coordinated spear‑phishing campaigns that compromise internal accounts and plant the backdoor for long‑term access.

Key Capabilities

  • Remote desktop & file management
  • Persistence through registry services or scheduled tasks
  • Credential dumping (SAM, LSASS), keylogging
  • Plug‑in architecture enabling modular extensions
  • Network reconnaissance and lateral movement
  • Exfiltration over HTTP(S) and DNS tunneling
  • Masquerading malware binaries and modules

ATT&CK Techniques

T1059
T1064
T1086
T1071.001
T1105
T1036
T1055
T1083

Recommended Actions

  • Deploy EDR solutions that flag unknown PowerShell scripts and process injections.
  • Monitor outbound traffic for unusual HTTP(S)/DNS connections to external IP addresses.
  • Implement application whitelisting and disable execution of unsigned code on Windows endpoints.
  • Regularly audit registry keys, scheduled tasks, and services for unknown entries.
  • Use endpoint file‑integrity monitoring to detect changes in system files or new binaries.
  • Block known NOKKI command‑and‑control domains/IPs via DNS filtering or firewall rules

Suggested Tags

RAT
Modular Ransomware
Konni Family
APT37
Windows Malware
Code Reuse

Confidence Assessment

The assessment is based primarily on publicly available Unit 42 reports and code overlap evidence with the Konni family. Specific indicators such as file hashes, domain names, or complete variant lists are not provided in the raw data, limiting the precision of detection signatures. Further analysis would require network‑capture or memory dump samples to confirm operational details.

Description

NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.(Citation: Unit 42 NOKKI Sept 2018)(Citation: Unit 42 Nokki Oct 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.