Naid

Naid is a trojan used by Elderwood to open a backdoor on compromised hosts. [1] [2]

ID: S0205
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 18 April 2018
Last Modified: 06 January 2021

Techniques Used

Domain ID Name Use
Enterprise T1112 修改注册表

Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk.[2]

Enterprise T1543 .003 创建或修改系统进程: Windows Service

Naid creates a new service to establish.[2]

Enterprise T1082 系统信息发现

Naid collects a unique identifier (UID) from a compromised host.[2]

Enterprise T1016 系统网络配置发现

Naid collects the domain name from a compromised host.[2]

Groups That Use This Software

ID Name References
G0066 Elderwood

[1]

References