Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors nblock

Also known as: tracked as, MaxTDS by FoxIT InTELL, ZeroAccess, Sirefef, MaxTDS, Threat Intelligence, Chimaera, Nemucod, Chanitor, APT34

Description

NBlock operates primarily through a layered delivery approach that fuses classic drive‑by exploitation, social engineering, and an expansive affiliate distribution model. Beginning with high‑volume malvertising campaigns that leveraged exploit kits such as Blackhole, Sakura, Sweet Orange, Nuclear Pack, Angler, and Neutrino, the actor distributes malware that can be a traditional ransomware payload (the NBlock variant) or an ad‑fraud trojan (Kovter). The installation chain typically delivers a Go‐based backdoor (various Giver/Lep/Pet/Kind flavors of GoGRPC) via a PowerShell one‑liner, establishes persistence through registry Run keys like “Realtek HD Audio” or MSI installers (RSOX), and then opens a gRPC/WebSocket tunnel on HTTPS/TLS to command and control. The backdoors maintain an encrypted heartbeat with the server, execute arbitrary shell commands, and support reverse SOCKS proxies to tunnel traffic. Once inside an environment, NBlock collects extensive system information—hostname, OS version, domain trust relationships, user accounts—with PowerShell scripts that also perform defense‑evasion checks (shadow copy deletion, BitLocker key removal, Windows Defender exclusion tampering). The actor then launches its ransomware engine which encrypts files and drops a ransom note (README_NBLOCK.txt). Double‑extortion is achieved by exfiltrating encrypted or otherwise valuable data via HTTPS PUT requests to AWS S3 buckets using the identifier "BackupAgent/1.0". Recently, the group has supplemented drive‑by infection with human‑influenced vectors: vishing over Microsoft Teams Quick Assist and WhatsApp messages that trigger automated ZIP sending across contact lists. These social‑engineering tactics often bypass traditional defenses by embedding malicious LNK files or Base64‑encoded PowerShell payloads inside attachments and rely on phishing‑style language to induce users to execute the code. A noticeable component of their operations is the use of typo‑squatted domains (e.g., sorvetenopotel) and custom HTTPS endpoints, which complicate straightforward domain filtering. NBlock’s infrastructure extends beyond malicious downloads; it comprises a network of proxy services—BlackHole, Sakura, Sweet Orange, Nuclear—and secure WebSocket tunnels with certificate pinning used by its SOCKS backdoors (RevSocket, RSOX, PyGRPC). This architecture obscures command and control by leveraging both TLS‑enabled gRPC channels on standard HTTPS ports and embedded HTTP/2 multiplexing, making signature‑based detection challenging.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Energy
Critical infrastructure
Non profit
Healthcare
Nuclear
Oil gas
Think tank
Maritime
Media
Information technology
Transportation
Aerospace
Hospitality
Education
Manufacturing
Construction

Targeted Countries / Regions

UA
US
IR
AE
SA
LB
TW
CN
BR
IL
CA
MX
RU
JP
BY

AI Analysis

Grounded in web research
· analyzed in 41 chunks · 1 week ago

Executive Summary

NBlock is a medium‑sophistication, financially motivated criminal ransomware actor that blends traditional exploit kit campaigns with modern backdoor and proxy infrastructure. The group deploys malvertising‑driven infections via a family of exploit kits (Blackhole, Sakura, Sweet Orange, Nuclear, Angler, Neutrino) to drop Go‑based backdoors, PowerShell reconnaissance tools and the NBlock ransomware, followed by double‑extortion tactics such as ransom notes and data exfiltration to AWS S3 buckets. Recent activity shows a shift toward social engineering over Microsoft Teams and WhatsApp to gain remote access and leverage a gRPC/WebSocket C2 channel that encrypts traffic on port 443.

Goals & Targeting

The strategic objective of NBlock centers on monetary gain through ransomware deployment and data monetization. The actor primarily targets mid‑to‑large organizations that can command high ransom payments, while also attempting to monetize stolen credentials or exfiltrated files independently. By maintaining a flexible delivery ecosystem—malvertising via exploit kits, direct phishing, social‑engineering vishing, and self‑propagating messaging apps—the group seeks broad reach and rapid infection velocity. The use of double‑extortion (data exfiltration + ransomware) indicates an intent to pressure victims into faster payouts and to extend the attack lifecycle beyond a single compromise.

Enhanced Description

Key Capabilities

  • Deploys malvertising campaigns via exploit kits (Blackhole, Sakura, Sweet Orange, Nuclear, Angler, Neutrino),
  • Installs Go‑based backdoors (GoGRPC variants) that communicate over encrypted gRPC/WebSocket tunnels on port 443
  • Persists through registry Run keys (e.g., “Realtek HD Audio”), MSI installers (RSOX), and hidden system files with attributes set to SYSTEM/Hidden
  • Executes PowerShell scripts for reconnaissance, credential harvesting, privilege escalation, and remote execution
  • Leverages SSH/SOCKS backdoors (RevSocket, RSOX, PyGRPC) for tunneling traffic
  • Exfiltrates data via HTTPS PUT to AWS S3 using custom User‑Agent "BackupAgent/1.0"
  • Employs double‑extortion with ransom notes (README_NBLOCK.txt) and encryption of victim files
  • Uses social engineering: PRISM‑themed ransom messages, fake legal notices, Microsoft Teams Quick Assist vishing, WhatsApp self‑propagation
  • Utilizes affiliate pyramid model for wide distribution with controlled IDs (5xx/6xx) and external distributors (8xx)
  • Disguises traffic with HTTPS, gRPC over HTTP/2, certificate pinning and custom protobuf messages
  • Maintains persistent communication with periodic heartbeats and optional remote command execution

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Command and Control
Impact
Credential Access
Collection
Exfiltration
Lateral Movement

ATT&CK Techniques

T1086
T1059.001
T1071.001
T1033
T1018
T1047
T1055
T1105
T1027
T1064
T1460
T1218.002
T1044
T1070.004
T1112
T1546.001
T1560
T1019
T1053.005
T1518.006

Software / Tooling

NBlock ransomware
GoGRPC backdoors (Giver, Lep, Pet, Kind variants)
BlindDoor
RevSocket
PyGRPC
S3Siphon
RSOX
MSI dropper
Blackhole exploit kit
Sakura EK
Sweet Orange EK
Nuclear Pack EK
Angler EK
Neutrino EK
Kovter
Cobalt Strike (used by affiliates)
Malvertising network domains
Telegram messenger (as C2 channel)

Campaigns & Victims

Initial reports of NBlock date back to 2026, but the actor’s modus operandi extends a decade through re‑use of legacy exploit kit infrastructure such as Kovter and KovCoreG from as early as 2011. The campaign pattern is characterized by high‑volume malvertising (averaging thousands of infections per day) followed by an evolution toward social engineering and lateral propagation over messaging apps. The affiliate model provides the group with broad reach but also introduces traceable IDs in download URLs. Victims have included mid‑size enterprises, educational institutions, and potentially government agencies, although public victim records remain scarce. The actor shows operational tempo that is opportunistic—spanning multiple vectors concurrently—and demonstrates resilience by shifting delivery assets (e.g., moving from HTML5/Flash CVE-2014‑0569 to HTTPS‑based payloads) to evade detection. Notable past operations include large‑scale Kovter ad‑fraud outbreaks on 2014‑2015, more recent exploitation of PowerShell via encoded one‑liners in 2026, and documented Vishing over Microsoft Teams for Quick Assist remote sessions. While the group is still active, it appears primarily opportunistic rather than mission‑driven with a focus on financial gain. IOC patterns

IOC Patterns

  • README_NBLOCK.txt ransom note
  • CVE-2014-0569 Flash vulnerability usage
  • Registry Run key name "Realtek HD Audio"
  • GoGRPC protobuf messages (RegisterRequest, ExecuteCommand)
  • Hidden/system file attributes on malicious binaries
  • Global\UUID mutex format
  • TLS-enabled WebSocket endpoint wss://[IP]/ws for gRPC
  • Custom User‑Agent 'BackupAgent/1.0' in AWS S3 PUT
  • Malicious domain names: justicehomeland.org, karmabelow80.org, handala-hack.to, handala-redwatned.to
  • Encrypted ZIP attachments used in WhatsApp self‑propagation
  • LNK shortcut files that launch PowerShell scripts
  • Typo‑squatted domain "sorvetenopotel"
  • Affiliate download IDs ranging 5xx/6xx and 8xx

Recommended Actions

  • Block outbound traffic to known C2 IP ranges and domains associated with NBlock (e.g., 23.227.*.*, justicehomeland.org, handala-hack.to)
  • Implement URL filtering or DNS sinkhole for malicious ad‑vertising domains identified in the malvertising network
  • Enforce patch management for Flash and other vulnerable components; disable legacy plugins where possible
  • Deploy application whitelisting or signed‑script controls to prevent execution of unsigned PowerShell scripts, LNK files and macro trojans
  • Enable Advanced Threat Protection or EDR solutions that detect gRPC/WebSocket traffic on port 443 and flag TLS certificate pinning anomalies
  • Monitor registry for new Run key entries matching “Realtek HD Audio” or other uncommon persistence values
  • Configure SIEM to alert on hidden/system file creation, mutex patterns "Global\UUID", and scheduled tasks created by unknown scripts
  • Restrict use of Microsoft Teams Quick Assist via policy; monitor for vishing calls and block remote assistance sessions initiated from unfamiliar users
  • Block or rate‑limit outbound HTTPS PUT requests with User‑Agent "BackupAgent/1.0" to prevent unauthorized S3 exfiltration
  • Deploy anti‑sandbox checks monitoring process creation of powershell_ise.exe, detect anti‑debugging probes
  • Restrict WhatsApp Web access on corporate devices and enforce multi‑factor authentication where feasible

Suggested Tags

ransomware
double-extortion
financial-motivated
malvertising
exploit-kit
GO-based-backdoor
PowerShell
gRPC-C2
SOCKS-proxy
affiliate-model
social-engineering
Zero-Day-CVE-2014-0569
WhatsApp-phishing
Teams-vishing
TLS-obfuscation
Iranian-associated

Confidence Assessment

The intelligence indicates a credible, financially driven ransomware actor that blends older exploitation tactics with modern backdoor capabilities. While the attack techniques and toolset are well documented, concrete evidence of recent high‑profile victim events is lacking; many observations stem from historical malvertising incidents or passive detection of infrastructure. Attribution to an Iranian state or affiliate network remains speculative. The assessment is moderate confidence: sufficient details exist on capabilities, delivery methods, and observed IOCs, but gaps remain regarding current operational tempo, exact victim scope, and the effectiveness of affiliate distribution channels.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 13 Domain 5 Filename 1 SHA-256 Hash 1

References

  1. https://www.cyfirma.com/news/weekly-intelligence-report-17-april-2026/ — Cited by AI analysis.
  2. https://www.ransomlook.io/browse — Cited by AI analysis.
  3. https://www.sophos.com/en-us/x-ops — Cited by AI analysis.
  4. https://www.darksignal.co/p/sentap-an-opportunistic-threat-actor — Cited by AI analysis.
  5. https://xsoar.pan.dev/docs/reference/integrations/group-ib-threat-intelligence--attribution — Cited by AI analysis.
  6. https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-kovcoreg-kovter-saga — Cited by AI analysis.
  7. https://docs-cortex.paloaltonetworks.com/c/Cortex-XDR/Cortex-XDR-5.x-Documentation/Set-up-malware-prevention-profiles — Cited by AI analysis.
  8. https://www.ransomware.live/groups — Cited by AI analysis.
  9. https://www.cybereason.com/fundamentals/what-are-advanced-persistent-threats — Cited by AI analysis.
  10. http://malware.dontneedcoffee.com/2013/08/prism-themed-ransomware.html — Cited by AI analysis.
  11. http://malware.dontneedcoffee.com/2014/10/cve-2014-0569.html — Cited by AI analysis.
  12. https://www.proofpoint.com/us/threat-insight/post/kovter-group-malvertising-campaign-exposes-millions-potential-ad-fraud-malware — Cited by AI analysis.
  13. https://blog.malwarebytes.com/threat-analysis/2015/08/large-malvertising-campaign-takes-on-yahoo/ — Cited by AI analysis.
  14. https://x.com/dilacer8/status/1973474128557646271 — Cited by AI analysis.
  15. attack.mitre.org — Cited by web research for: Threat Intelligence
  16. www.zscaler.com — Cited by web research for: PowerShell scripts
  17. www.trendmicro.com — Cited by web research for: Education

Intel Summary

18

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

ransomware
apt-like
cybercrime
financial-gain
double-extortion
financial-motivated
malvertising
exploit-kit
GO-based-backdoor
PowerShell
gRPC-C2
SOCKS-proxy
affiliate-model
social-engineering
Zero-Day-CVE-2014-0569
WhatsApp-phishing
Teams-vishing
TLS-obfuscation
Iranian-associated

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.