Naikon__2021__Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN.pdf
ID: aa36b899-23a7-4f48-bc27-a570241af273
STIX ID: report--aa36b899-23a7-4f48-bc27-a570241af273
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2021-04-27
Last Modified Date: 2021-04-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender Labs documents a multi-year (Jun 2019–Mar 2021) cyber-espionage campaign attributed to the NAIKON APT targeting Southeast Asian military organizations; actors used DLL sideloading and SFX droppers to deploy the RainyDay backdoor and a secondary Nebulae backdoor, executed credential-dumping, network scanning and automated exfiltration (including Dropbox uploads), and maintained persistence via services, scheduled tasks and registry Run keys — the report provides technical analysis, MITRE ATT&CK mappings and numerous IOCs (file hashes, domains, IPs) to support detection and response.
