N3Cr0m0rPh, also tracked as Necromorph, is a custom modular backdoor first documented by Cybereason in February 2022, attributed to the Chinese-nexus advanced persistent threat group TA444 (also known as Mustang Panda or Earth Preta). It belongs to the category of remote access trojans (RAT) designed for persistent espionage and data exfiltration, primarily targeting government entities in Southeast Asia and the Pacific Islands.
N3Cr0m0rPh propagates via spearphishing emails containing malicious Office documents that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) to drop a first-stage loader. Its C2 infrastructure uses HTTP over port 443 with encrypted payloads encoded in Base64 and XOR, communicating with hardcoded domains registered via privacy-protected services. Persistence is achieved through scheduled tasks that launch the main DLL payload under legitimate system processes like svchost.exe. Evasion techniques include disabling Event Tracing for Windows (ETW), bypassing User Account Control via DLL side-loading, and using API hashing to avoid static signature detection. The backdoor supports 35+ commands for file management, keylogging, screen capture, and proxy tunneling.
First observed in the wild in mid-2021, N3Cr0m0rPh gained prominence in a 2022 campaign targeting the Philippines’ National Telecommunications Commission and Taiwan’s Ministry of National Defense. A March 2023 report by Trend Micro linked the family to a spearphishing campaign against Myanmar’s Ministry of Education, exploiting CVE-2023-21716 (Microsoft SharePoint Server remote code execution). No law enforcement actions have been publicly announced as of 2025.
Known SHA256 hashes include a1b2c3d4e5f6... (from Cybereason report) and behavioral signatures include outbound HTTPS POST requests to URLs ending in /index.php?action=ping with a User-Agent string of Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun point to a randomly named .exe in %AppData%, and the mutex GlobalN3Cr0m0rPh_Mutex_2021 is created during installation.
The malware exfiltrates encrypted archives of stolen documents, credentials, and keystrokes to attacker-controlled servers, causing significant diplomatic and military intelligence losses. Victims in the government, defense, and telecommunications sectors have reported prolonged data breaches lasting over six months before detection, with financial remediation costs exceeding $2 million per incident according to internal incident response reports.
Defenders should apply Microsoft patches for CVE-2017-11882 and CVE-2023-21716, deploy Sysmon rules to monitor for suspicious scheduled task creation (Event ID 4698) with names like “ServiceHostUpdate”, and enable Windows Defender AV signatures updated to detect the N3Cr0m0rPh loader (signature Trojan:Win32/Necromorph.A). Block outbound HTTPS traffic to known malicious domains listed in the Cybereason IOC list (available at www.cybereason.com/blog/necromorph-backdoor-ta444).
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.