Skip to main content

Analysis of Turla's Neuron and Nautilus Tools

An analysis of two tools, Neuron and Nautilus, used by the Turla advanced persistent threat (APT) group has been released. These are highly developed tools, capable of targeting both client and server devices and maintaining persistent network access.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

An analysis of two tools, Neuron and Nautilus, used by the Turla advanced persistent threat (APT) group has been released. These are highly developed tools, capable of targeting both client and server devices and maintaining persistent network access.

Affected platforms

The following platforms are known to be affected:

Threat details

These are highly developed tools, capable of targeting both client and server devices and maintaining persistent network access.

Neuron uses a server and client model, where a compromised server (typically a mail or web server) within a target organisation acts as an infection vector and internal command and control (C2) server for client systems. The installation of an internal C2 server, inside the target network, allows it to evade detection by network gateway-based monitoring. While external communications are required for connections back to an upstream C2 infrastructure, these communications are often encrypted using the legitimate transport layer security (TLS) configuration of the victim network. Neuron also uses legitimate Windows terms for its files and communications, allowing it to maintain persistence more easily.

The primary purpose of the Neuron service is to control Neuron clients and act as an exit node for exfiltrated data. Servers are typically infected via brute-force attacks, exploitation of application layer vulnerabilities or server misconfigurations. A dropper is then used to deliver the Neuron service payload, which installs itself as an automatic service to persist through server restarts. The service then establishes a HTTP listener (port 80 or 443) to monitor for specific uniform resource identifiers (URI) that denote communications from Neuron clients.

The Neuron client is intended to collect information including credentials, files and metadata from users which it then sends to the Neuron service. Infection occurs via spear-phishing using a macro-enabled document as a dropper.

Nautilus appears similar to Neuron, but uses differing names for its files and services. Nautilus is used to perform functions on client devices based on commands sent from the C2 server. Functions include executing commands, manipulating files and shutting down a system.

Update 19 Jan 2018 

The Nation Cyber Security Centre has released new information on Neuron and Nautilus, indicating the Turla group have updated them with new capabilities. These modifications are sufficient to avoid previous signatures and indicators of compromise. A summary of the changes is given below:

  • AES encryption has replaced RC4 in certain cases.
  • Communications have been modified to better avoid detection.
  • The .NET payload is now memory-resident.

Threat updates

Date Update
19 Jan 2018 Threat update

The Nation Cyber Security Centre has released new information on Neuron and Nautilus, indicating the Turla group have updated them with new capabilities. These modifications are sufficient to avoid previous signatures and indicators of compromise. A summary of the changes is given below:

  • AES encryption has replaced RC4 in certain cases.
  • Communications have been modified to better avoid detection.
  • The .NET payload is now memory-resident.

Remediation advice

Organisations should ensure that:

Remediation steps

Type Step
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, antivirus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place and password reuse is discouraged.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from infected machines should be reset on a clean computer.

For further information on these threats please review the NCSC Advisory


Last edited: 4 November 2020 3:51 pm