Ninja
MITRE ATT&CK: S1100 View on attack.mitre.org
Aliases: Ninja
- First seen
- 2020-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-09-01 19:11:49
- Profile updated
- 2026-07-07 13:01:18
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:fr country_code:de country_code:cn
Context
Ninja is a malware developed in C++ that has been used by ToddyCat to penetrate networks and control remote systems since at least 2020. Ninja is possibly part of a post exploitation toolkit exclusively used by ToddyCat and allows multiple operators to work simultaneously on the same machine. Ninja has been used against government and military entities in Europe and Asia and observed in specific infection chains being deployed by Samurai.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Ninja (S1100). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 54.38.214.230 | 2026-09-02 | 4 |
| IP address | 51.195.149.127 | 2026-09-02 | 2 |
Detection coverage
- 354 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Spearphishing via Service (attack-pattern)
- Malicious File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Native API (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Scheduled Transfer (attack-pattern)
- DLL (attack-pattern)
- System Information Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Data Obfuscation (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Environmental Keying (attack-pattern)
- Internal Proxy (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Rundll32 (attack-pattern)
- Process Injection (attack-pattern)
- Windows Service (attack-pattern)
- Process Discovery (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Web Protocols (attack-pattern)
- Compression (attack-pattern)
Used by threat actors
- ToddyCat (threat-actor)
Reports & references
- Kaspersky — 106799 (report)
- MITRE ATT&CK — S1100 (report)