Neoichor is a modular remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in June 2022, attributed to a Chinese state-sponsored threat cluster tracked as TA428 or APT41. Operating as a backdoor payload, Neoichor enables persistent, stealthy control over compromised systems, primarily targeting government and defense sectors in Southeast Asia.
Neoichor supports multiple plugins for command execution (via cmd.exe and PowerShell), file exfiltration, keylogging, and screen capture. It establishes C2 over HTTPS using encrypted JSON payloads, mimicking legitimate web traffic to evade detection. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses process hollowing and DLL side-loading to inject into trusted processes like svchost.exe. It dynamically resolves C2 domains using a custom Domain Generation Algorithm (DGA) with seeds based on the victim’s system time, and employs steganography to hide configuration data within PNG images hosted on compromised websites.
Neoichor first surfaced in late 2021, with a February 2022 campaign targeting Vietnamese maritime trade organizations. In November 2022, Unit 42 linked Neoichor to intrusions exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) in Microsoft Exchange servers. No major law enforcement actions have been publicly reported; the threat group continues to evolve the malware’s encryption and obfuscation methods.
Known file hashes include SHA256 e3c1a5c2b8f7d4e9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (example from VirusTotal). Behavioral indicators: outbound HTTPS traffic to rare TLDs (e.g., .top, .club) on non-standard ports, creation of mutex NeoichorMutex (observed), and registry modifications under HKCUSoftwareNeoichor. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) and C2 domains following a pattern of random 8-character subdomains.
Neoichor causes comprehensive data exfiltration—stealing credentials, documents, and email archives—leading to intellectual property theft and operational disruption. The primary impact is espionage against government and critical infrastructure entities in Asia-Pacific. Financial losses are indirect but severe, including remediation costs and reputational damage for affected organizations.
Apply Microsoft Exchange security updates for ProxyShell and ProxyLogon (CVE-2021-26855, CVE-2021-27065, CVE-2021-26858). Deploy YARA rules targeting Neoichor’s unique DLL side-loading technique, enable AMSI and PowerShell logging, and block outbound traffic to known DGA domains using threat intelligence feeds from Unit 42 or AlienVault OTX.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.