Analysis of Turla's Neuron and Nautilus Tools
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
These are highly developed tools, capable of targeting both client and server devices and maintaining persistent network access.
Neuron uses a server and client model, where a compromised server (typically a mail or web server) within a target organisation acts as an infection vector and internal command and control (C2) server for client systems. The installation of an internal C2 server, inside the target network, allows it to evade detection by network gateway-based monitoring. While external communications are required for connections back to an upstream C2 infrastructure, these communications are often encrypted using the legitimate transport layer security (TLS) configuration of the victim network. Neuron also uses legitimate Windows terms for its files and communications, allowing it to maintain persistence more easily.
The primary purpose of the Neuron service is to control Neuron clients and act as an exit node for exfiltrated data. Servers are typically infected via brute-force attacks, exploitation of application layer vulnerabilities or server misconfigurations. A dropper is then used to deliver the Neuron service payload, which installs itself as an automatic service to persist through server restarts. The service then establishes a HTTP listener (port 80 or 443) to monitor for specific uniform resource identifiers (URI) that denote communications from Neuron clients.
The Neuron client is intended to collect information including credentials, files and metadata from users which it then sends to the Neuron service. Infection occurs via spear-phishing using a macro-enabled document as a dropper.
Nautilus appears similar to Neuron, but uses differing names for its files and services. Nautilus is used to perform functions on client devices based on commands sent from the C2 server. Functions include executing commands, manipulating files and shutting down a system.
Update 19 Jan 2018
The Nation Cyber Security Centre has released new information on Neuron and Nautilus, indicating the Turla group have updated them with new capabilities. These modifications are sufficient to avoid previous signatures and indicators of compromise. A summary of the changes is given below:
- AES encryption has replaced RC4 in certain cases.
- Communications have been modified to better avoid detection.
- The .NET payload is now memory-resident.
Threat updates
| Date | Update |
|---|---|
| 19 Jan 2018 |
Threat update
The Nation Cyber Security Centre has released new information on Neuron and Nautilus, indicating the Turla group have updated them with new capabilities. These modifications are sufficient to avoid previous signatures and indicators of compromise. A summary of the changes is given below:
|
Remediation advice
Organisations should ensure that:Remediation steps
| Type | Step |
|---|---|
For further information on these threats please review the NCSC Advisory |
Last edited: 4 November 2020 3:51 pm