Skip to main content
Mallory
MalwareUsed by 6 actors

NetDraft

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAT-8302

The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.

via cyber security newscybersecuritynews.com
Webworm

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor)... ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin... Solar... has given it the name LuckyStrike Agent.

via the hacker newsthehackernews.com
Earth Alux

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor)... ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin... Solar... has given it the name LuckyStrike Agent.

via the hacker newsthehackernews.com
Space Pirates

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor)... ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin... Solar... has given it the name LuckyStrike Agent.

via the hacker newsthehackernews.com
LongNosedGoblin

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor)... ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin... Solar... has given it the name LuckyStrike Agent.

via the hacker newsthehackernews.com
Erudite Mogwai

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor)... ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin... Solar... has given it the name LuckyStrike Agent.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1053.005Scheduled TaskEvidence1

The script may be persisted to collect system information via a scheduled task... schtasks /create ... Since NetDraft is missing the capability to persist across reboots and relogins, one of the first commands the C2 issues to it is the creation of a malicious scheduled task

T1059Command and Scripting InterpreterEvidence1
TacticExecution

NetDraft and FringePorch support the following functionalities: Execute arbitrary commands on the endpoint ... CloudSorcerer v3 ... execute arbitrary commands

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

The script may be persisted to collect system information via a scheduled task... schtasks /create ... Since NetDraft is missing the capability to persist across reboots and relogins, one of the first commands the C2 issues to it is the creation of a malicious scheduled task

T1053.005Scheduled TaskEvidence1

The script may be persisted to collect system information via a scheduled task... schtasks /create ... Since NetDraft is missing the capability to persist across reboots and relogins, one of the first commands the C2 issues to it is the creation of a malicious scheduled task

T1102Web ServiceEvidence1

FINALDRAFT uses legitimate services such as MS Graph to act as command-and-control servers (C2s)... NetDraft relies on the MS Graph API to communicate with its OneDrive based C2... CloudSorcerer v3 will contact GitHub to obtain C2 information... or read a GameSpot profile

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app28 days ago
hash.sha256●●●●●●●●●●●●View more in app28 days ago
hash.sha256●●●●●●●●●●●●View more in app28 days ago
uri●●●●●●●●●●●●View more in app29 days ago
domain●●●●●●●●●●●●View more in app29 days ago
uri●●●●●●●●●●●●View more in app29 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution6

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.