NedDnLoader
- First seen
- 2022-05-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Profile updated
- 2026-07-07 12:58:33
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption. It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma. The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Neddnloader_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Report2020Overwatchnowheretohide (report)
- Kaspersky — 109490 (report)
- clearskysec.com — Dream Job Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Neddnloader (report)
- telsy.com — Lazarus Gate (report)
- McAfee — Operation North Star A Job Offer Thats Too Good To Be True (report)
- McAfee — Operation North Star Behind The Scenes (report)