Malware
Royal DNS
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
Royal DNS is a Windows malware family operated by Mirage.
Background
RoyalDNS is a backdoor employed by APT15 that tunnels its operations over DNS and maintains persistence on the host by installing a service named 'Nwsapagent'.
Source: Malpedia (Fraunhofer FKIE).