S0395: LightNeuron
LightNeuron is a sophisticated backdoor that has targeted Microsoft Exchange servers since at least 2014. LightNeuron has been used by Turla to target diplomatic and foreign affairs-related organizations. The presence of certain strings in the malware suggests a Linux variant of LightNeuron exists.[1]
Security context for executives and security teams
S0395: LightNeuron describes [LightNeuron](https://attack.mitre.org/software/S0395) is a sophisticated backdoor that has targeted Microsoft Exchange servers since at least 2014. [LightNeuron](https://attack.mitre.org/software/S0395) has been used by [Turla](https://attack.mitre.org/groups/G0010) to target diplomatic and foreign affairs-related organizations. The presence of certain strings in the malware suggests a Linux variant of [LightNeuron](https://attack.mitre.org/software/S0395) exists.(Citation: ESET LightNeuron May 2019)
Executive priority
S0395: LightNeuron is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0395: LightNeuron by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows, Linux), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0395: LightNeuron appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
LightNeuron
LightNeuron is a sophisticated backdoor that has targeted Microsoft Exchange servers since at least 2014. LightNeuron has been used by Turla to target diplomatic and foreign affairs-related organizations. The presence of certain strings in the malware suggests a Linux variant of LightNeuron exists.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1070.004 | File DeletionSub-technique | LightNeuron has a function to delete files.[1] |
| Enterprise | T1071.003 | Mail ProtocolsSub-technique | LightNeuron uses SMTP for C2.[1] |
| Enterprise | T1029 | Scheduled Transfer | LightNeuron can be configured to exfiltrate data during nighttime or working hours.[1] |
| Enterprise | T1020 | Automated Exfiltration | LightNeuron can be configured to automatically exfiltrate files under a specified directory.[1] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | LightNeuron exfiltrates data over its email C2 channel.[1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | LightNeuron encrypts its configuration files with AES-256.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | LightNeuron has used AES and XOR to decrypt configuration files and commands.[1] |
| Enterprise | T1560 | Archive Collected Data | LightNeuron contains a function to encrypt and store emails that it collects.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as |
| Enterprise | T1114.002 | Remote Email CollectionSub-technique | LightNeuron collects Exchange emails matching rules specified in its configuration.[1] |
| Enterprise | T1082 | System Information Discovery | LightNeuron gathers the victim computer name using the Win32 API call |
| Enterprise | T1105 | Ingress Tool Transfer | LightNeuron has the ability to download and execute additional files.[1] |
| Enterprise | T1119 | Automated Collection | LightNeuron can be configured to automatically collect files under a specified directory.[1] |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | LightNeuron uses AES to encrypt C2 traffic.[1] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | LightNeuron can store email data in files and directories specified in its configuration, such as |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | LightNeuron is capable of executing commands via cmd.exe.[1] |
| Enterprise | T1005 | Data from Local System | LightNeuron can collect files from a local system.[1] |
| Enterprise | T1565.002 | Transmitted Data ManipulationSub-technique | LightNeuron is capable of modifying email content, headers, and attachments during transit.[1] |
| Enterprise | T1016 | System Network Configuration Discovery | LightNeuron gathers information about network adapters using the Win32 API call |
| Enterprise | T1106 | Native API | LightNeuron is capable of starting a process using CreateProcess.[1] |
| Enterprise | T1505.002 | Transport AgentSub-technique | LightNeuron has used a malicious Microsoft Exchange transport agent for persistence.[1] |
| Enterprise | T1001.002 | SteganographySub-technique | LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.[1] |
Groups, software, and campaigns
G0010: Turla
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.2 | Current bundle | 2cc5c37de1d9… | ||
| 19.1 | 1.2 | Older bundle | 2cc5c37de1d9… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]ESET LightNeuron May 2019
Faou, M. (2019, May). Turla LightNeuron: One email away from remote code execution. Retrieved June 24, 2019.
Open source URL - [2]mitre-attackS0395Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
