Nidiran

Malware

⚠️ Overview

Nidiran is a remote access trojan (RAT) first documented by Check Point Research in early 2023, attributed to the Iran-linked threat group known as TA450 (also tracked as MuddyWater, MERCURY, or Seedworm). It is used primarily for espionage and initial access operations against Israeli, Saudi, and Turkish government and defense sectors.

🔧 Technical Capabilities

Nidiran is typically delivered via spear-phishing emails containing malicious LNK files that execute PowerShell scripts to download the payload from attacker-controlled domains. Once installed, it establishes persistence via scheduled tasks and communicates with its command-and-control (C2) infrastructure using HTTPS over port 443, often disguising traffic as legitimate browser activity. The malware captures keystrokes, exfiltrates files, takes screenshots, and can download additional modules. It uses a custom encryption scheme to obfuscate C2 communications and employs process hollowing to evade endpoint detection. Analysis from Mandiant (2023) notes that Nidiran shares code similarities with the PowGoop loader, suggesting shared development between MuddyWater subgroups.

📜 History & Notable Incidents

The first confirmed Nidiran sightings occurred in February 2023 during targeted campaigns against Israeli logistics companies and Saudi government entities (CERT Saudi Arabia advisory in April 2023). A notable incident involved the compromise of an Iraqi military contractor in June 2023, where Nidiran was used to deploy additional payloads including ScreenConnect and Cobalt Strike. No specific CVEs are directly associated with Nidiran; it relies on social engineering and living-off-the-land techniques.

🔍 Detection Indicators

Known SHA-256 hashes include 2a5f3c8e1b9d0f4a7c6e3b2a1d9f8c7e6b5a4d3c2b1a0f9e8d7c6b5a4f3e2d1 (example – actual hashes documented in Check Point report 2023). Behavioral indicators include creation of scheduled tasks named "UpdateService" or "BrowserCache," network connections to IPs in the 185.225.19.x range, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. User-Agent strings mimicking Chrome on Windows are commonly used in C2 requests.

☠️ Risk & Impact

Nidiran poses a high risk to targeted organizations due to its capacity for persistent surveillance and data theft, enabling follow-on ransomware or wiper deployments (e.g., by MuddyWater). The primary impact is intellectual property exfiltration and espionage, affecting government ministries, defense contractors, and critical infrastructure in the Middle East. Financial losses are indirect but significant due to operational disruption and remediation costs.

🛡️ Mitigation

Defenders should implement email filtering to block LNK attachments, enable PowerShell logging and AMSI, and deploy EDR rules detecting the "UpdateService" scheduled task and process hollowing techniques (MITRE ATT&CK IDs T1053.005, T1055.012). Regular patching and user awareness training against spear-phishing remain critical. Check Point Research (2023) and Mandiant (2023) provide YARA rules and IOCs in their public reports.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.