NOKKI
S0353 · Windows
NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap with the KONNI malware family.
There is some evidence potentially linking NOKKI to APT37.
ATT&CK S0353
Sigma rules0
YARA rules0
Live IOCs0