NSPX30
- First seen
- 2021-05-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-05-06 16:56:38
- Profile updated
- 2026-07-07 13:11:16
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:ru
Context
NSPX30 is a remote access tool known to target government and technology sectors. It facilitates unauthorized access to networks for intelligence gathering purposes.
Detection coverage
- 2 YARA rules
Detection rules
- MALPEDIA_Win_Nspx30_Auto (yara-rule)
- SEKOIA_Apt_Blackwood_Nspx30_Plugin (yara-rule)
Reports & references
- ESET — Nspx30 Sophisticated Aitm Enabled Implant Evolving Since 2005 (report)
- blog.sonicwall.com — Blackwood Apt Group Has A New Dll Loader (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nspx30 (report)
- jsac.jpcert.or.jp — Jsac2024 1 2 Facundo En (report)