SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nikitear (Back to overview)

NikiTeaR

Actor(s): Kimsuky

VTCollection    

NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT.

It supports the following commands:

- srun <EXEC> <ARGS>: Executing arbitrary commands with elevated privileges.
- up/down <FILENAME>: Performing remote file operations (upload/download).
- screen: Capturing screenshots for reconnaissance.
- conn <IP_ADDRESS> <PORT>: Establishing a reverse shell
- memload <EXPORT>: Loading additional DLL into memory.
- die <COMMAND>: Terminates the process and remove trace

It is delivered via a multi-staged execution chain, beginning with a Golang-based dropper that executes a loader, a DLL with the internal name MemLoad_V3.dll, capable of loading DLL reflectively.

Its internal DLL name is httptroy_dll.dll.

To resist analysis, the backdoor is heavily obfuscated; it utilizes custom hashing to conceal Windows API calls, and employs a combined Base64+XOR encryption for C&C traffic and internal character strings, which are dynamically reconstructed at runtime.

References
2025-10-30 ⋅ Gen Digital ⋅ Alexandru-Cristian Bardaș
DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant
ComeBacker DRATzarus NikiTeaR
2025-10-18 ⋅ Twitter (@ThreatrayLabs) ⋅ Threatray Labs
Tweet on Kimsuky activity with loaders delivering HttpSpy and HttpTroy
NikiTeaR
Yara Rules
[TLP:WHITE] win_nikitear_auto (20260917 | Detects win.nikitear.)
rule win_nikitear_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nikitear."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nikitear"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c8d4d81 448bd1 6690 410fbe09 8bd1 80e941 8bc2 }
            // n = 7, score = 100
            //   4c8d4d81             | jmp                 0xf2d
            //   448bd1               | movzx               eax, byte ptr [ebp - 0x1f]
            //   6690                 | inc                 ecx
            //   410fbe09             | mov                 ecx, eax
            //   8bd1                 | inc                 esp
            //   80e941               | mov                 byte ptr [ebp - 0x13], al
            //   8bc2                 | cmp                 al, 0x20

        $sequence_1 = { 4584e4 480f45cf 4d8bce 4c8bc0 }
            // n = 4, score = 100
            //   4584e4               | cmp                 al, 0x20
            //   480f45cf             | jl                  0xadc
            //   4d8bce               | inc                 ecx
            //   4c8bc0               | mov                 ecx, eax

        $sequence_2 = { 410fb6c2 c0e804 c0e104 02c8 44884c2420 440fb6c1 400fb6c5 }
            // n = 7, score = 100
            //   410fb6c2             | push                edi
            //   c0e804               | inc                 ecx
            //   c0e104               | push                esi
            //   02c8                 | dec                 eax
            //   44884c2420           | lea                 ebp, [esp - 0x7f0]
            //   440fb6c1             | dec                 eax
            //   400fb6c5             | sub                 esp, 0x8f0

        $sequence_3 = { 0fb6442461 8bcf 40887c246c 3c20 7c0f 3c7e 7f0b }
            // n = 7, score = 100
            //   0fb6442461           | mov                 word ptr [esi], ax
            //   8bcf                 | dec                 eax
            //   40887c246c           | lea                 edi, [esi + 3]
            //   3c20                 | dec                 ecx
            //   7c0f                 | lea                 ecx, [esp + eax]
            //   3c7e                 | dec                 esp
            //   7f0b                 | mov                 esi, eax

        $sequence_4 = { 83e10f 4a0fbe841908460300 428a8c1918460300 482bd0 8b42fc d3e8 49895108 }
            // n = 7, score = 100
            //   83e10f               | movzx               eax, word ptr [edx + 8]
            //   4a0fbe841908460300     | inc    ecx
            //   428a8c1918460300     | mov                 eax, eax
            //   482bd0               | shr                 eax, 1
            //   8b42fc               | test                ecx, ecx
            //   d3e8                 | jns                 0x10f8
            //   49895108             | sub                 eax, ecx

        $sequence_5 = { 7358 0fb6c1 4c8d0516e00000 41f644400201 7405 0fb6c9 eb25 }
            // n = 7, score = 100
            //   7358                 | je                  0x1b1c
            //   0fb6c1               | cmp                 al, 0x20
            //   4c8d0516e00000       | jge                 0x1ad8
            //   41f644400201         | dec                 eax
            //   7405                 | mov                 edi, 0x84222325
            //   0fb6c9               | in                  al, 0x9c
            //   eb25                 | bnd retf            

        $sequence_6 = { 480fbe841108460300 8a8c1118460300 4c2bc0 418b40fc d3e8 4d894708 41894718 }
            // n = 7, score = 100
            //   480fbe841108460300     | mov    ecx, dword ptr [ebp + 0x80]
            //   8a8c1118460300       | dec                 ecx
            //   4c2bc0               | arpl                word ptr [ecx], dx
            //   418b40fc             | dec                 eax
            //   d3e8                 | sar                 edx, 6
            //   4d894708             | dec                 esp
            //   41894718             | lea                 eax, [0x11c38]

        $sequence_7 = { 33d2 89442450 ffc8 8bf8 410fb68c80e2610300 }
            // n = 5, score = 100
            //   33d2                 | mov                 dl, 0x3f
            //   89442450             | mov                 dword ptr [esp + 0x38], 0x213c2616
            //   ffc8                 | mov                 word ptr [esp + 0x3c], 0x1d
            //   8bf8                 | mov                 dword ptr [esp + 0x36], 0x70
            //   410fb68c80e2610300     | mov    edi, 0x75

        $sequence_8 = { 33c0 418b4908 41894104 450fb74204 418bc0 d1e8 }
            // n = 6, score = 100
            //   33c0                 | dec                 esp
            //   418b4908             | lea                 eax, [ebp - 0x3f]
            //   41894104             | inc                 esp
            //   450fb74204           | mov                 ecx, ecx
            //   418bc0               | nop                 
            //   d1e8                 | inc                 ecx

        $sequence_9 = { 488b442478 420fb70400 0fafc2 0500040000 c1f80b 66418900 410fb74202 }
            // n = 7, score = 100
            //   488b442478           | mov                 byte ptr [ebx], 0xff
            //   420fb70400           | dec                 eax
            //   0fafc2               | mov                 eax, dword ptr [ecx + 0x3df0]
            //   0500040000           | mov                 edx, 1
            //   c1f80b               | dec                 eax
            //   66418900             | mov                 ecx, ebx
            //   410fb74202           | dec                 eax

    condition:
        7 of them and filesize < 610304
}
Download all Yara Rules