Skip to content

S1192 NICECURL

NICECURL is a VBScript-based backdoor used by APT42 to download additional modules.1

Item Value
ID S1192
Associated Names
Type MALWARE
Version 1.0
Created 08 January 2025
Last Modified 08 January 2025
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1071 Application Layer Protocol -
enterprise T1071.001 Web Protocols NICECURL has used HTTPS for C2 communications.1
enterprise T1059 Command and Scripting Interpreter NICECURL has provided an arbitrary command execution interface.1
enterprise T1573 Encrypted Channel -
enterprise T1573.002 Asymmetric Cryptography NICECURL has used HTTPS for C2 communications.1
enterprise T1070 Indicator Removal -
enterprise T1070.004 File Deletion NICECURL has a function to remove artifacts.1
enterprise T1105 Ingress Tool Transfer NICECURL has the ability to download additional content onto an infected machine, e.g. by using curl.1

Groups That Use This Software

ID Name References
G1044 APT42 1

References