Malware
NimbleMamba
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn.
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.
Family metadata imported from Malpedia (Fraunhofer FKIE).