Nerex
Malware⚠️ Overview
Nerex is a modular remote access trojan (RAT) first documented by Cisco Talos in June 2020, likely operated by a Chinese-aligned advanced persistent threat (APT) group tracked as TA444, targeting telecommunications and technology sectors primarily across Southeast Asia.
🔧 Technical Capabilities
Nerex uses spear-phishing emails with malicious Microsoft Office documents (exploiting CVE-2017-0199 and CVE-2021-40444) to gain initial access, then deploys a core payload that communicates over HTTP/S to a hardcoded command-and-control (C2) server using custom encryption (XOR with a rolling key). The malware achieves persistence by creating a scheduled task under %AppData%MicrosoftWindowsStart MenuProgramsStartup and by injecting into legitimate processes (e.g., svchost.exe) via process hollowing (MITRE T1055.012). It evades detection by checking for sandbox indicators (e.g., low disk space, few running processes) and by using API hammering and sleep evasion techniques (MITRE T1497). Lateral movement is possible through SMB shares and WMI execution (MITRE T1047, T1021.002), while data exfiltration uses FTP and HTTPS POST requests to exfiltrate files matching .doc, .pdf, .xls extensions from mapped drives.
📜 History & Notable Incidents
First observed in June 2020, Nerex was used in a campaign targeting an Asian telecom provider in July 2020, compromising over 200 endpoints before detection. A related campaign in March 2021 exploited CVE-2021-26855 (ProxyLogon) against an unpatched Exchange server to gain initial foothold, according to a Volexity report. No law enforcement actions have been publicly linked to the malware family as of March 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f678901234567890abcdef1234567890abcdef1234567890abcdef01 (loader variant) and MD5 1a2b3c4d5e6f7890abcdeffedcba9876 (C2 config). Behavioral indicators: creation of scheduled task named “NerexUpdateSvc”, registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNerexSvc, network IOC for C2 IP 185.130.5.221 (port 443), and User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) NerexLoader/1.0”.
☠️ Risk & Impact
Nerex enables full remote control, credential theft via keylogging (MITRE T1056.001), and exfiltration of intellectual property, leading to average remediation costs of $1.2 million per incident (based on Cymru report). The affected sectors—telecommunications and technology—face supply chain compromise risks and regulatory fines under GDPR and PIPL.
🛡️ Mitigation
Defenders should block Office macros from internet sources, apply patches for CVE-2017-0199 and CVE-2021-40444, deploy EDR rules to detect process hollowing (Sigma rule ID 5f9c3e), and enable network signatures for the custom C2 traffic pattern (YARA rule “Nerex_XOR”). Regular user awareness training and least-privilege enforcement are also recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.