Neoichor

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Neoichor](https://attack.mitre.org/software/S0691) is C2 malware used by [Ke3chang](https://attack.mitre.org/groups/G0004) since at least 2019; similar malware families used by the group include Leeson and Numbldea.(Citation: Microsoft NICKEL December 2021)

Associated Techniques (11)
ID ATT&CK Tactics
T1005 Data from Local System -
T1016 System Network Configuration Discovery -
T1016.001 Internet Connection Discovery -
T1033 System Owner/User Discovery -
T1070 Indicator Removal -
T1071.001 Web Protocols -
T1082 System Information Discovery -
T1105 Ingress Tool Transfer -
T1112 Modify Registry -
T1559.001 Component Object Model -
T1614.001 System Language Discovery -
Used by Actors (1)
Metadata
ID: 208
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00