Description
NGLite is a backdoor trojan that runs commands received through its command and control channel. Its distinguishing feature is a novel C2 channel that uses a decentralized network based on the legitimate NKN protocol, which avoids the fixed infrastructure most backdoors depend on.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
5 techniques across 2 tactics.
Alert name variants
| Alert Name |
|---|
| Win32.Backdoor.Nglite |
| Win64.Backdoor.Nglite |