Nosedive
- Malware type
- botnet, ddos, dropper
- Family
- Malware family
- Profile updated
- 2026-07-07 14:28:13
Context
According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT architectures (e.g. MIPS, ARM, SuperH, PowerPC, etc.). Nosedive implants are typically deployed from Tier 2 payload servers in the Raptor Train infrastructure through a unique URL encoding scheme and domain injection method. Nosedive droppers use this method to request payloads for specific C2s by encoding the requested C2 domain and joining it with a unique "key" that identifies the bot and the target architecture of the compromised device (e.g. MIPS, ARM, etc.), which is then injected into the Nosedive implant payload that is deployed to the Tier 1 node. Once deployed, Nosedive runs in-memory only and allows the operators to execute commands, upload and download files, and run DDoS attacks on compromised devices. The malware and its associated droppers are memory-resident only and deleted from disk. This, in addition to anti-forensics techniques employed on these devices including the obfuscation of running process names, compromising devices through a multi-stage infection chain, and killing remote management processes, makes detection and forensics much more difficult.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Elf_Nosedive_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Nosedive (report)
- media.defense.gov — Csa Prc Linked Actors Botnet (report)
- justice.gov — Redacted 24 Mj 1484 Signed Search And Seizure Warrant For Disclosure (report)
- blog.lumen.com — Derailing The Raptor Train (report)
- assets.lumen.com — Raptor Train Handbook Copy (report)