Nexus

First seen
2023-02-15 00:00:00
Malware type
botnet, credential-stealer, trojan
Family
Malware family
Last IoC activity
2026-07-17 08:55:16
Profile updated
2026-07-07 14:08:36

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:ca country_code:gb

Context

Nexus is a sophisticated banking trojan targeting financial institutions, primarily in North America and Europe. It is known for stealing credentials and integrating with botnet infrastructures.

Detection coverage

  • 9 YARA rules

Used by threat actors

  • Cutting Edge (campaign)
  • FLORAHOX Activity (campaign)
  • Ivanti VPN Zero-Day Exploit Activity (CVE-2025-0282) (campaign)
  • June 2023 Citrix Vulnerability Exploitation (campaign)
  • SPACEHOP Activity (campaign)
  • Velvet Ant Cisco Network Switches Exploit Activity (CVE-2024-20399) (campaign)
  • Velvet Ant F5 BIG-IP Espionage Activity (campaign)

Detection rules

  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_3 (yara-rule)
  • SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTORM_2 (yara-rule)
  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_1 (yara-rule)
  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_2 (yara-rule)
  • SIGNATURE_BASE_WEBSHELL_G_APT_Backdoorwebshell_SLAYSTYLE_1 (yara-rule)
  • SIGNATURE_BASE_WEBSHELL_G_APT_Backdoorwebshell_SLAYSTYLE_2 (yara-rule)
  • SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTEAL_1 (yara-rule)
  • SIGNATURE_BASE_MAL_G_Dropper_BRICKSTEAL_1 (yara-rule)
  • SIGNATURE_BASE_MAL_G_Dropper_BRICKSTEAL_2 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Nexus (report)
  • cleafy.com — Nexus A New Android Botnet (report)
  • liansecurity.com (report)

External references