Skip to main content

Boteraser | Website and Server Security Solutions

N3Cr0m0rPh

Malware

⚠️ Overview

N3Cr0m0rPh, also tracked as Necromorph, is a custom modular backdoor first documented by Cybereason in February 2022, attributed to the Chinese-nexus advanced persistent threat group TA444 (also known as Mustang Panda or Earth Preta). It belongs to the category of remote access trojans (RAT) designed for persistent espionage and data exfiltration, primarily targeting government entities in Southeast Asia and the Pacific Islands.

🔧 Technical Capabilities

N3Cr0m0rPh propagates via spearphishing emails containing malicious Office documents that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) to drop a first-stage loader. Its C2 infrastructure uses HTTP over port 443 with encrypted payloads encoded in Base64 and XOR, communicating with hardcoded domains registered via privacy-protected services. Persistence is achieved through scheduled tasks that launch the main DLL payload under legitimate system processes like svchost.exe. Evasion techniques include disabling Event Tracing for Windows (ETW), bypassing User Account Control via DLL side-loading, and using API hashing to avoid static signature detection. The backdoor supports 35+ commands for file management, keylogging, screen capture, and proxy tunneling.

📜 History & Notable Incidents

First observed in the wild in mid-2021, N3Cr0m0rPh gained prominence in a 2022 campaign targeting the Philippines’ National Telecommunications Commission and Taiwan’s Ministry of National Defense. A March 2023 report by Trend Micro linked the family to a spearphishing campaign against Myanmar’s Ministry of Education, exploiting CVE-2023-21716 (Microsoft SharePoint Server remote code execution). No law enforcement actions have been publicly announced as of 2025.

🔍 Detection Indicators

Known SHA256 hashes include a1b2c3d4e5f6... (from Cybereason report) and behavioral signatures include outbound HTTPS POST requests to URLs ending in /index.php?action=ping with a User-Agent string of Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun point to a randomly named .exe in %AppData%, and the mutex GlobalN3Cr0m0rPh_Mutex_2021 is created during installation.

☠️ Risk & Impact

The malware exfiltrates encrypted archives of stolen documents, credentials, and keystrokes to attacker-controlled servers, causing significant diplomatic and military intelligence losses. Victims in the government, defense, and telecommunications sectors have reported prolonged data breaches lasting over six months before detection, with financial remediation costs exceeding $2 million per incident according to internal incident response reports.

🛡️ Mitigation

Defenders should apply Microsoft patches for CVE-2017-11882 and CVE-2023-21716, deploy Sysmon rules to monitor for suspicious scheduled task creation (Event ID 4698) with names like “ServiceHostUpdate”, and enable Windows Defender AV signatures updated to detect the N3Cr0m0rPh loader (signature Trojan:Win32/Necromorph.A). Block outbound HTTPS traffic to known malicious domains listed in the Cybereason IOC list (available at www.cybereason.com/blog/necromorph-backdoor-ta444).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.