NOKKI
MITRE ATT&CK: S0353 View on attack.mitre.org
Aliases: NOKKI
- First seen
- 2018-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:41:39
Targeted industries: government-and-public-sector defense-and-aerospace
Context
NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.
Detection coverage
- 1 YARA rules
- 363 Sigma rules
Malware & tools used
- System Time Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- File Deletion (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Rundll32 (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Local Data Staging (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Credential API Hooking (attack-pattern)
- File Transfer Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
Used by threat actors
- Kimsuky (threat-actor)
Detection rules
- MALPEDIA_Win_Nokki_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- cocomelonc.github.io — Malware Tricks 46 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nokki (report)
- researchcenter.paloaltonetworks.com — Unit42 Nokki Almost Ties The Knot With Dogcall Reaper Group Uses New Malware To Deploy Rat (report)
- researchcenter.paloaltonetworks.com — Unit42 New Konni Malware Attacking Eurasia Southeast Asia (report)
- MITRE ATT&CK — S0353 (report)