NedDnLoader

First seen
2022-05-01 00:00:00
Malware type
downloader
Family
Malware family
Profile updated
2026-07-07 12:58:33

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption. It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma. The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Neddnloader_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — Report2020Overwatchnowheretohide (report)
  • Kaspersky — 109490 (report)
  • clearskysec.com — Dream Job Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Neddnloader (report)
  • telsy.com — Lazarus Gate (report)
  • McAfee — Operation North Star A Job Offer Thats Too Good To Be True (report)
  • McAfee — Operation North Star Behind The Scenes (report)

External references