NOKKI

MITRE ATT&CK: S0353 View on attack.mitre.org

Aliases: NOKKI

First seen
2018-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:41:39

Targeted industries: government-and-public-sector defense-and-aerospace

Context

NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.

Detection coverage

  • 1 YARA rules
  • 363 Sigma rules

Malware & tools used

  • System Time Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Rundll32 (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Local Data Staging (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Credential API Hooking (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Nokki_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • cocomelonc.github.io — Malware Tricks 46 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nokki (report)
  • researchcenter.paloaltonetworks.com — Unit42 Nokki Almost Ties The Knot With Dogcall Reaper Group Uses New Malware To Deploy Rat (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Konni Malware Attacking Eurasia Southeast Asia (report)
  • MITRE ATT&CK — S0353 (report)

External references