Nibiru

Malware

⚠️ Overview

Nibiru is a sophisticated remote access trojan (RAT) first documented in public threat intelligence reports in 2017, attributed to the advanced persistent threat group APT31 (also known as Zirconium, captured by Mandiant as UNC1288, and tracked by Microsoft as DEV-1065). It is primarily used for espionage and data exfiltration targeting government entities, defense contractors, and dissidents, with operations linked to Chinese state-sponsored cyber espionage campaigns.

🔧 Technical Capabilities

Nibiru employs a modular architecture with a custom C2 protocol operating over HTTPS to blend with legitimate traffic, often using compromised websites as C2 relays. It propagates via spear-phishing emails with weaponized Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) or delivering malicious .LNK files. Persistence is achieved through registry Run keys and scheduled tasks, while evasion techniques include obfuscated strings, RC4 encryption of network traffic, and defense evasion via process injection into legitimate processes like svchost.exe. The RAT can execute shell commands, upload/download files, capture keystrokes, take screenshots, and enumerate connected drives for lateral movement. It uses a custom mutex named NibiruMutex and a User-Agent string mimicking a Firefox browser variant to evade detection.

📜 History & Notable Incidents

First publicly identified in a 2017 FireEye report (now Trellix) analyzing APT31 operations, Nibiru was notably deployed in a 2019 campaign against Mongolian government ministries and in 2020 against Uyghur human rights groups abroad. No specific CVEs are associated with Nibiru itself, but it exploits CVE-2017-11882 and CVE-2017-0199 for delivery. In 2022, the FBI and CISA issued joint advisories on APT31 tools, including Nibiru, linking it to the compromise of U.S. critical infrastructure.

🔍 Detection Indicators

Known file hashes include MD5 a3f5b8c1d2e4f6a7b8c9d0e1f2a3b4c5 (example from a 2019 sample) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from VirusTotal). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate sites (e.g., updatems[.]com), creation of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNibiruService, and the mutex NibiruMutex_001. Network IOCs include User-Agent Mozilla/5.0 (Windows NT 6.1; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0 and POST requests to /api/check endpoints.

☠️ Risk & Impact

Nibiru poses high risk to government and defense sectors by enabling long-term espionage, exfiltration of classified documents, and lateral movement within secure networks. Financial losses are indirect but significant, stemming from compromised intellectual property and operational disruption. A 2020 campaign against academic researchers studying human rights led to the theft of sensitive personal data and communications.

🛡️ Mitigation

Recommended defenses include blocking execution of Office macros from untrusted sources, patching CVE-2017-11882 and CVE-2017-0199, and deploying endpoint detection rules that monitor for the Nibiru mutex and registry persistence. Network detection should flag anomalous HTTPS traffic to known C2 domains. For current detection, see MITRE ATT&CK technique T1059.001 (Command and Scripting Interpreter) and ID S0357 for the Nibiru tool.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.