NOKKI — Malware Profile
NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family. There is some evidence potentially linking NOKKI to APT37.
MITRE ATT&CK techniques (16)
- T1016 System Network Configuration Discovery
- T1027 Obfuscated Files or Information
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1056.004 Credential API Hooking
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1071.002 File Transfer Protocols
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1218.011 Rundll32
- T1547.001 Registry Run Keys / Startup Folder
- T1680 Local Storage Discovery