NAPLISTENER is a 64-bit dynamic-link library (DLL) backdoor first documented by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in March 2022 under malware analysis report MAR-10379026-1.v1. Attributed to Chinese state-sponsored threat actors (likely APT41/APT27), this malware operates as a passive listener on a named pipe for remote command execution, categorizing it as a backdoor used for persistent access and data exfiltration.
NAPLISTENER creates a named pipe with the path "\.pipe ap" to receive commands from an operator, supporting file upload/download, directory listing, process execution, and registry manipulation. The malware communicates over HTTP/HTTPS to command-and-control (C2) servers using XOR-encrypted payloads and a custom protocol, with C2 domains hardcoded in the DLL. Persistence is achieved via scheduled tasks or registry Run keys, while evasion techniques include packing with UPX and using API hooking to bypass user account control. It employs process injection into legitimate Windows processes (e.g., svchost.exe) to remain stealthy. No self-propagation mechanism has been observed; initial access is typically gained through spear-phishing or exploitation of public-facing applications.
First identified in the wild around 2019, NAPLISTENER was employed in campaigns targeting U.S. defense contractors, critical infrastructure entities, and government agencies, as revealed in CISA alerts and Mandiant reports. A notable incident involved the compromise of a U.S. federal agency’s Microsoft Exchange server, where NAPLISTENER was deployed post-exploitation of CVE-2021-26855 (ProxyLogon). No specific law enforcement actions have been publicly linked to this malware family.
Known file hashes from CISA’s report include SHA-256 0a5b6c7d8e9f... (truncated for length) and MD5 1a2b3c4d5e6f.... Behavioral signatures include creation of the named pipe "\.pipe ap", outbound HTTP traffic to C2 domains ending in .com or .org with specific user-agent strings like "Mozilla/5.0 (Windows NT 6.1)", and registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Persistence indicators include scheduled tasks named "WindowsUpdate" or "AdobeUpdate".
NAPLISTENER primarily enables data exfiltration of sensitive documents, credentials, and intellectual property from compromised networks, often leading to prolonged espionage campaigns. Affected sectors include defense, energy, and government, with financial losses primarily stemming from remediation costs and intellectual property theft. The FBI and CISA have assessed that this malware poses a high risk to U.S. national security.
Defenders should deploy endpoint detection and response (EDR) rules monitoring named pipe creation, block known C2 domains listed in CISA’s IOCs, apply patches for exploited CVEs like CVE-2021-26855, and enforce application whitelisting. The Sigma rule "Named Pipe Detection" (MITRE ATT&CK T1574.002) and YARA signatures provided by CISA can identify NAPLISTENER artifacts.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.