Executive Summary
NOKKI is a modular Windows RAT first seen in early 2018, sharing code with the Konni family and likely employed by APT37. It provides persistent remote control, credential theft, and covert exfiltration via legitimate protocols, complicating detection. The malware’s plugin architecture allows attackers to expand capabilities dynamically.
Enhanced Description
NOKKI is a modular, Windows‑based remote access trojan that first surfaced in January 2018. The code base demonstrates significant overlap with the Konni family, suggesting shared development lineage or common authorship. Analysts have linked NOKKI to APT37 operations, and it has been discussed extensively by Unit 42 in their 2018 reports. Like its Konni counterpart, NOKKI is engineered for stealth and persistence. The toolkit includes a plug‑in architecture that allows operators to inject additional modules at runtime—enabling functionalities such as keylogging, credential dumping, remote file management, and lateral movement. Persistence mechanisms typically involve registry service creations or scheduled tasks, while clean‑up routines may remove registry entries upon disconnection. The RAT’s modularity also permits exfiltration over legitimate protocols, usually HTTP(S) or DNS tunneling, obfuscating traffic from baseline anomaly detection systems. When combined with APT37 activity, NOKKI is implicated in coordinated spear‑phishing campaigns that compromise internal accounts and plant the backdoor for long‑term access.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on publicly available Unit 42 reports and code overlap evidence with the Konni family. Specific indicators such as file hashes, domain names, or complete variant lists are not provided in the raw data, limiting the precision of detection signatures. Further analysis would require network‑capture or memory dump samples to confirm operational details.
NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.(Citation: Unit 42 NOKKI Sept 2018)(Citation: Unit 42 Nokki Oct 2018)