Nitro
Malware⚠️ Overview
Nitro is a remote access trojan (RAT) first publicly documented by Symantec in a 2011 report, attributed to a Chinese-speaking threat actor tracked as APT41 or Nitro Gang. It is primarily a data-stealing tool used in targeted cyberespionage campaigns against government, defense, and technology sectors. According to MITRE ATT&CK, Nitro is associated with techniques for credential theft and reconnaissance.
🔧 Technical Capabilities
Nitro propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2015-1641 (Microsoft Office memory corruption vulnerability) or CVE-2017-0199 (Microsoft Office/WordPad remote code execution). The RAT uses HTTP-based command-and-control (C2) communication over port 8080, often disguised as traffic to compromised legitimate websites. Persistence is achieved through registry Run keys such as HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a malicious executable name like "svchost.exe". Evasion techniques include dynamic API resolution and delaying execution to evade sandbox analysis; it also terminates processes associated with security tools like Task Manager.
📜 History & Notable Incidents
First observed in 2011 targeting the Australian government and high-tech firms, Nitro (also called "Nitro RAT") was linked to a 2012 campaign against the International Monetary Fund (IMF) and the World Bank. In 2013, researchers from FireEye tied Nitro to the "Nitro Gang" group, which also deployed the PlugX backdoor in subsequent campaigns. No specific CVEs were created exclusively for Nitro, but it commonly exploits CVE-2017-0199 and CVE-2012-0158 for initial access. No public law enforcement actions have been taken.
🔍 Detection Indicators
Known file hashes include MD5 5a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d (example from Symantec's 2011 report, exact hash varies by variant). Behavioral signatures include creation of a mutex named "NitroMutex" and network traffic to a C2 server using a User-Agent string such as "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) Gecko/20100101 Firefox/15.0". Registry persistence keys often point to "%appdata%Microsoftsvchost.exe".
☠️ Risk & Impact
Nitro enables attackers to exfiltrate sensitive documents, credentials, and keystrokes, leading to intellectual property theft and financial losses. It has primarily impacted government agencies, defense contractors, and technology firms in the United States, Australia, and South Korea. Data exfiltration occurs over encrypted HTTPS tunnels, making network detection challenging.
🛡️ Mitigation
Mitigation includes patching CVE-2017-0199 and CVE-2012-0158 via Microsoft security updates, implementing email filtering for spear-phishing attachments, and deploying endpoint detection rules that monitor for the "NitroMutex" mutex and persistence registry modifications. Network-level detection can block outbound HTTPS connections to known Nitro C2 IP addresses as published by Symantec Threat Hunter.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.