Register to stream ATT&CKcon 2.0 October 29-30


Naid is a trojan used by Elderwood to open a backdoor on compromised hosts. [1] [2]

ID: S0205
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1043 Commonly Used Port Naid connects to external C2 infrastructure over port 443. [2]
Enterprise T1094 Custom Command and Control Protocol Naid connects to C2 infrastructure and establishes backdoors over a custom communications protocol. [2] [3]
Enterprise T1112 Modify Registry Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk. [2]
Enterprise T1050 New Service Naid creates a new service to establish. [2]
Enterprise T1082 System Information Discovery Naid collects a unique identifier (UID) from a compromised host. [2]
Enterprise T1016 System Network Configuration Discovery Naid collects the domain name from a compromised host. [2]

Groups That Use This Software

ID Name References
G0066 Elderwood [1]