Nexus
- First seen
- 2023-02-15 00:00:00
- Malware type
- botnet, credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-17 08:55:16
- Profile updated
- 2026-07-07 14:08:36
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ca country_code:gb
Context
Nexus is a sophisticated banking trojan targeting financial institutions, primarily in North America and Europe. It is known for stealing credentials and integrating with botnet infrastructures.
Detection coverage
- 9 YARA rules
Used by threat actors
- Cutting Edge (campaign)
- FLORAHOX Activity (campaign)
- Ivanti VPN Zero-Day Exploit Activity (CVE-2025-0282) (campaign)
- June 2023 Citrix Vulnerability Exploitation (campaign)
- SPACEHOP Activity (campaign)
- Velvet Ant Cisco Network Switches Exploit Activity (CVE-2024-20399) (campaign)
- Velvet Ant F5 BIG-IP Espionage Activity (campaign)
Detection rules
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_3 (yara-rule)
- SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTORM_2 (yara-rule)
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_1 (yara-rule)
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_2 (yara-rule)
- SIGNATURE_BASE_WEBSHELL_G_APT_Backdoorwebshell_SLAYSTYLE_1 (yara-rule)
- SIGNATURE_BASE_WEBSHELL_G_APT_Backdoorwebshell_SLAYSTYLE_2 (yara-rule)
- SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTEAL_1 (yara-rule)
- SIGNATURE_BASE_MAL_G_Dropper_BRICKSTEAL_1 (yara-rule)
- SIGNATURE_BASE_MAL_G_Dropper_BRICKSTEAL_2 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Nexus (report)
- cleafy.com — Nexus A New Android Botnet (report)
- liansecurity.com (report)