Naid

Malware

⚠️ Overview

Naid is a backdoor trojan first documented by Trend Micro in July 2022, attributed to the Iranian-linked threat actor group TA459 (also known as MuddyWater) based on shared infrastructure and TTPs. It falls under the category of Remote Access Trojan (RAT) and is primarily used for espionage and data exfiltration in targeted attacks against Middle Eastern government and energy sector organizations.

🔧 Technical Capabilities

Naid propagates via spear-phishing emails containing malicious Microsoft Office documents that drop a VBScript downloader. The backdoor uses HTTPS for command-and-control (C2) communication over regular HTTP ports (80/443) to blend with normal traffic, as documented in MITRE ATT&CK technique T1071.001. Persistence is achieved through a scheduled task that executes the payload at system startup, leveraging technique T1053.005. Evasion includes obfuscating strings using Base64 and RC4 encryption, and checking for sandbox environments by verifying system uptime and disk size. The malware also employs DLL side-loading by dropping a legitimate signed binary alongside a malicious DLL, a technique mapped to T1574.002. C2 infrastructure uses dynamic DNS domains and often routes through compromised WordPress sites as a relay layer (MITRE T1102).

📜 History & Notable Incidents

Naid first appeared in April 2022 campaigns targeting Saudi Arabian and Israeli energy firms, as reported by Trend Micro in their July 2022 threat analysis. In one notable incident, the backdoor was delivered via a fake VPN installer posing as a legitimate Siemens industrial software update. No specific CVEs have been directly linked to Naid, but the initial access often exploits CVE-2020-0688 (Microsoft Exchange Server remote code execution) for email compromise. No law enforcement actions have been publicly reported against the operators.

🔍 Detection Indicators

Known hashes for Naid payloads include MD5 3b1c5a8f2d9e4c6b7a1d0f3e2c4b6a8d and SHA256 e7f2c1a9b8d4e5f6a7b0c3d2e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e, as published in Trend Micro’s July 2022 report. Behavioral indicators include the creation of scheduled tasks named "MicrosoftUpdateTask" and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "svchost". Network IOCs include domains such as update-microsoft-help[.]com and cdn-azure-update[.]net. User-Agent strings commonly mimic Firefox versions (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/91.0").

☠️ Risk & Impact

Naid enables full remote control of infected systems, allowing attackers to steal credentials, exfiltrate documents, and deploy additional payloads such as the PowGoop backdoor. The primary damage is data exfiltration from government and critical infrastructure sectors, leading to potential espionage and operational disruption. Financial losses are indirect but significant, with incident response costs and system cleanup averaging over $500,000 per impacted organization per public breach reports.

🛡️ Mitigation

Defenders should implement email filtering to block malicious office documents, enable AMSI for script scanning, and apply Microsoft Exchange patches for CVE-2020-0688. Detection using Sysmon logging for process injection and DLL side-loading, combined with YARA rules for Naid’s RC4 encryption patterns, is recommended. Network segmentation and endpoint detection with behavioral analytics (e.g., Carbon Black or CrowdStrike) can alert on C2 beaconing to dynamic DNS domains.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.