logo

Naikon__2021__Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN.pdf

ID: aa36b899-23a7-4f48-bc27-a570241af273

STIX ID: report--aa36b899-23a7-4f48-bc27-a570241af273

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2021-04-27

Last Modified Date: 2021-04-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender Labs documents a multi-year (Jun 2019–Mar 2021) cyber-espionage campaign attributed to the NAIKON APT targeting Southeast Asian military organizations; actors used DLL sideloading and SFX droppers to deploy the RainyDay backdoor and a secondary Nebulae backdoor, executed credential-dumping, network scanning and automated exfiltration (including Dropbox uploads), and maintained persistence via services, scheduled tasks and registry Run keys — the report provides technical analysis, MITRE ATT&CK mappings and numerous IOCs (file hashes, domains, IPs) to support detection and response.