Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0630
malware
Nebulae
Nebulae Is a backdoor that has been used by Naikon since at least 2020.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 16
uses
T1105
Ingress Tool Transfer
uses
T1680
Local Storage Discovery
uses
T1005
Data from Local System
uses
T1095
Non-Application Layer Protocol
uses
T1547.001
Registry Run Keys / Startup Folder
uses
T1057
Process Discovery
uses
T1106
Native API
uses
T1036.004
Masquerade Task or Service
uses
T1070.004
File Deletion
uses
T1543.003
Windows Service
uses
T1036.005
Match Legitimate Resource Name or…
uses
T1574.001
DLL
uses
T1059.003
Windows Command Shell
uses
T1083
File and Directory Discovery
uses
T1573.001
Symmetric Cryptography
uses by
G0019
Naikon