Naikon

Aliases: Sacto

First seen
2015-04-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-06-16 02:00:35
Profile updated
2026-07-07 12:36:28

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:ph country_code:th

Context

Naikon is a cyber espionage malware attributed to a state-sponsored group focusing on intelligence gathering. It primarily targets government and public sector entities in Southeast Asia using remote access Trojan capabilities.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Naikon_Auto (yara-rule)

Reports & references

  • Kaspersky — The Naikon Apt (report)
  • Mandiant — Rpt Apt30 (report)
  • web.archive.org — Globalthreatintelreport (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Naikon (report)

External references