LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0118: Nidiran

Nidiran is a custom backdoor developed and used by Suckfly. It has been delivered via strategic web compromise. [1]

EnterpriseS0118MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Nidiran matters because ATT&CK describes it as a custom Windows backdoor associated with Suckfly and delivery via strategic web compromise. For leaders, the practical issue is not just the malware name: it points to the need to validate whether Windows environments can detect backdoor persistence through services, disguised task or service names, and external tool transfer activity after an initial web-based compromise.

Executive priority

Prioritize this as a readiness and evidence question: can the organization prove it monitors Windows service creation/modification, suspicious service naming, and inbound file/tool transfer activity well enough to support incident response decisions? This is relevant to business continuity because a backdoor with service-based persistence can extend attacker dwell time if service inventory, endpoint telemetry, and SOC triage processes are weak.

Technical view

ATT&CK provides no object-level detection text for Nidiran, so defenders should pivot to the related behaviors: T1543.003 Windows Service, T1036.004 Masquerade Task or Service, and T1105 Ingress Tool Transfer. Validate visibility for Windows service creation and modification, service executable paths and registry-backed configuration, anomalous or misleading service names/descriptions, and file transfers from external systems into compromised hosts. Because the malware platform is Windows, Windows endpoint and service telemetry should be the primary validation focus.

Likely telemetry

  • Windows service creation, modification, start, stop, and configuration change records
  • Windows Registry data related to service configuration and executable paths
  • Endpoint process execution and parent/child process context for service-hosted payloads
  • File creation and download/transfer evidence on Windows hosts
  • Network connection logs showing external transfer activity into endpoints

Detection direction

  • Hunt for newly created or modified Windows services with unusual executable paths, names, descriptions, or recovery commands.
  • Compare service and task names against known-good enterprise baselines to identify masquerading rather than relying only on malware signatures.
  • Correlate suspected service persistence with external file transfer activity consistent with Ingress Tool Transfer.
  • Tune detections to reduce false positives from legitimate software deployment, administrative tooling, and patch management activity.
  • Use the Suckfly relationship as threat-intelligence context only; do not assume attribution from a single Nidiran-like behavior.

Mitigation priorities

  • Maintain an authoritative inventory and baseline of approved Windows services and scheduled tasks.
  • Restrict and monitor administrative permissions capable of creating or modifying Windows services.
  • Ensure endpoint logging captures service configuration changes and file transfer artifacts needed for IR reconstruction.
  • Review web compromise response playbooks so endpoint persistence checks are included after suspected strategic web compromise exposure.
  • Use detection engineering tests around T1543.003, T1036.004, and T1105 to validate SOC coverage rather than treating the malware family name as the primary control point.
Additional notes and limits

The most useful defensive framing is behavior-based. The supplied ATT&CK relationships show Nidiran using masqueraded tasks/services, ingress tool transfer, and Windows services, which gives SOC and IR teams concrete validation targets even though no official detection text is provided.

ATT&CK fields supplied here do not include aliases, detailed procedures, indicators, hashes, C2 infrastructure, or official detection logic. Tactics are not specified on the malware object itself. Local telemetry, baselines, and incident evidence are required before drawing conclusions about exposure, detection coverage, or attribution.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Nidiran

Nidiran is a custom backdoor developed and used by Suckfly. It has been delivered via strategic web compromise. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

3 rows
DomainIDNameRelationship / procedure
EnterpriseT1105Ingress Tool Transfer

Nidiran can download and execute files.[3]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager), which mimics the legitimate Microsoft database by the same name.[3][4]

EnterpriseT1543.003Windows ServiceSub-technique

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager).[3]

Associated objects

Groups, software, and campaigns

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
084f8c6a9baa3c9f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle084f8c6a9baa…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  2. [2]
    Symantec Suckfly May 2016

    DiMaggio, J. (2016, May 17). Indian organizations targeted in Suckfly attacks. Retrieved August 3, 2016.

  3. [3]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  4. [4]
    Microsoft SAM

    Microsoft. (2006, October 30). How to use the SysKey utility to secure the Windows Security Accounts Manager database. Retrieved August 3, 2016.

    Open source URL
  5. [5]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  6. [6]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  7. [7]
    mitre-attackS0118
    Open source URL
  8. [8]
    mitre-attackS0118
    Open source URL
  9. [9]
    mitre-attackS0118
    Open source URL
  10. [10]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  11. [11]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  12. [12]
    Symantec Suckfly May 2016

    DiMaggio, J. (2016, May 17). Indian organizations targeted in Suckfly attacks. Retrieved August 3, 2016.

  13. [13]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  14. [14]
    Microsoft SAM

    Microsoft. (2006, October 30). How to use the SysKey utility to secure the Windows Security Accounts Manager database. Retrieved August 3, 2016.

    Open source URL
  15. [15]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  16. [16]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  17. [17]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.