NGLite

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[NGLite](https://attack.mitre.org/software/S1106) is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.(Citation: NGLite Trojan)

Associated Techniques (5)
ID ATT&CK Tactics
T1016 System Network Configuration Discovery -
T1033 System Owner/User Discovery -
T1071.001 Web Protocols -
T1090.003 Multi-hop Proxy -
T1573.001 Symmetric Cryptography -
Metadata
ID: 329
Created: 13/01/2026 17:48
Updated: 10/05/2026 04:00