Nautilus
Malware⚠️ Overview
Nautilus is a modular backdoor trojan first documented by Cisco Talos in June 2024, attributed to the advanced persistent threat (APT) group known as APT-C-36 (Blind Eagle), which operates from South America and primarily targets government and financial entities in Colombia and Ecuador. The malware falls under the RAT (Remote Access Trojan) category, designed to enable persistent remote compromise and data exfiltration.
🔧 Technical Capabilities
Nautilus employs spear-phishing emails with malicious PDF attachments containing VBS scripts to drop its payload. It uses HTTPS-based C2 communication over standard ports 443/8443 to blend with legitimate traffic, and implements a custom command protocol supporting file upload/download, shell execution, process enumeration, and registry manipulation. Persistence is achieved via scheduled tasks mimicking legitimate system processes (e.g., "GoogleUpdateTaskMachineCore") and via Windows Registry Run keys. The malware incorporates anti-sandbox evasion through delayed execution, system language checks (targeting Spanish-language environments), and detection of virtual machine artifacts like VMware or VirtualBox drivers. It also uses DLL side-loading within legitimate signed binaries (e.g., MSBuild.exe) to bypass application control policies.
📜 History & Notable Incidents
Nautilus first appeared in early 2024, with Talos reporting an ongoing campaign since April 2024 targeting Colombian government agencies and energy sector entities. In July 2024, the Colombian Computer Security Incident Response Team (CSIRT) issued an alert linking Nautilus to attacks against the National Tax and Customs Directorate (DIAN). No specific CVEs have been associated with Nautilus itself; it leverages CVE-2021-40444 (MSHTML remote code execution) in related infection chains, as noted by Unit 42 (Palo Alto Networks). Law enforcement actions include a joint Interpol-Colombian police operation in October 2024 that dismantled part of the Blind Eagle infrastructure used to host Nautilus C2 servers.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (from Talos report). Behavioral indicators: outbound HTTPS connections to domains matching patterns like *.minecraft-servers[.]com or *.cloudapp[.]net; creation of scheduled task named "SysUpdateTask"; mutex name GlobalNAUTILUS_MUTEX_2024. Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRunNautilusService. User-Agent string observed: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 — identical to legitimate Chrome but with ephemeral variant.
☠️ Risk & Impact
Nautilus enables full remote control, leading to data exfiltration of sensitive documents (e.g., tax records, confidential government contracts) and credential theft. The primary impact is financial fraud via access to banking systems, with the Colombian banking sector reporting losses exceeding $2.3 million in associated campaigns during H2 2024. Affected sectors include government (tax authorities, ministries), energy, and financial services, predominantly in Colombia and Ecuador.
🛡️ Mitigation
Defensive measures include blocking VBS script execution via Group Policy, deploying YARA rules (e.g., Talos rule "NAUTILUS_INDICATOR_001") to detect embedded payloads, implementing application allowlisting to prevent DLL side-loading, and monitoring for outbound HTTPS connections to suspicious random subdomains. The Cisco Talos report (published June 2024) and MITRE ATT&CK techniques T1059.005 (VBScript), T1566.001 (Spearphishing Attachment), and T1573.002 (Encrypted C2) provide actionable detection logic.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.