REF2924 is a cyberespionage group targeting South Asia, known for its 'Naplistener' data-stealing malware.
Analyst brief
REF2924 is a group tracked by Elastic Security Labs, primarily targeting victims operating in southern and southeast Asia. The actor wields a novel data-stealing malware named 'Naplistener' by researchers, which is an HTTP listener written in C#. Key TTPs include the use of this custom malware for data exfiltration and likely leveraging HTTP protocol for C2 communications to evade network-based detection systems. Defenders should focus on unusual HTTP listener processes, suspicious network traffic, and activities that may exploit the limitations of network-based defenses prevalent in the targeted region.
REF2924
unknown
A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the researchers — in attacks against victims operating in southern and southeast Asia.According to a blog post by Elastic senior security research engineer Remco Sprooten, in that region of the world, network-based detection and prevention technologies are the de facto method for securing many environments.