Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Neunative

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1112Modify RegistryEvidence1

The usr and userid UUIDs are generated once with UuidCreate and persisted in the registry at HKCU\Software\Neunative under _uuid ; the inst UUID identifies the install.

Stealth

1 technique
T1036MasqueradingEvidence1

The Accept header is pixel-perfect Chrome... The User-Agent is SDK... Someone spent real effort getting the Accept header exactly right, then set the User-Agent to a three-character string that gives the disguise away.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

The usr and userid UUIDs are generated once with UuidCreate and persisted in the registry at HKCU\Software\Neunative under _uuid ; the inst UUID identifies the install.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence1

For each peer server, the SDK opens a TLS connection on port 6000 and speaks a proprietary binary protocol... The message types, recovered from the factory and RTTI symbols: Register, RegisterResponse, Ping, OpenTunnel, TunnelMessage, CloseTunnel, Goodbye. | The SDK contacts lb.gmslb[.]net:443 (TLS) with an HTTP GET that reads like a browser doing its best impression of itself: GET /regdev?usr=<uuid>&userid=<uuid>&dev_ip=<ip>&sdkv=8.0.36&inst=<uuid> HTTP/1.1

T1090.002External ProxyEvidence1

Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.

T1568Dynamic ResolutionEvidence1

The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ; the server numbers overlap... The sN identifier and IP are the stable node identity. The domain is disposable.

INDICATORS OF COMPROMISE

IOCs tracked for this family

56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
50 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
5 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 days ago
domain●●●●●●●●●●●●View more in app2 days ago
domain●●●●●●●●●●●●View more in app3 days ago
domain●●●●●●●●●●●●View more in app3 days ago
domain●●●●●●●●●●●●View more in app3 days ago
domain●●●●●●●●●●●●View more in app3 days ago
ACTIVITY FEED

Recent activity

1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching56

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.