Netskope Threat Labs

NGLite

ATP Sandbox Adv. Heuristics

NGLite is a backdoor trojan that runs commands received through its command and control channel. Its distinguishing feature is a novel C2 channel that uses a decentralized network based on the legitimate NKN protocol, which avoids the fixed infrastructure most backdoors depend on.

First seen
May 2022
Last seen
September 2026

5 techniques across 2 tactics.

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery

TA0011 Command and Control

Alert Name
Win32.Backdoor.Nglite
Win64.Backdoor.Nglite