Skip to content

Malware

NimbleMamba

NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn.

NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.


Family metadata imported from Malpedia (Fraunhofer FKIE).