Skip to content

Neshta

Neshta is a long-standing Windows file-infector virus first seen in the early 2000s that infects executable files by prepending its own code while also overwriting the beginning of the host file and storing displaced original bytes at the end.

Profile source: Mallory opens in a new tab

Neshta

Family profile

Neshta is a long-standing Windows file-infector virus first seen in the early 2000s that infects executable files by prepending its own code while also overwriting the beginning of the host file and storing displaced original bytes at the end. Because it does not merely append or prepend data cleanly, remediation is more complex than simply stripping a viral stub. When an infected executable is launched, Neshta reconstructs the original host in a temporary directory and executes that clean copy to reduce user suspicion, while also maintaining its own execution path on the system.

Neshta establishes persistence by dropping a copy of itself under the Windows directory and hijacking the executable file open command so that it runs whenever a user starts an EXE file. It also creates a mutex to avoid multiple concurrent instances. The malware enumerates local, removable, and mapped network drives and infects additional executable files, while skipping some system and program directories and applying size-based checks to candidate files. It can clear read-only attributes on target files before infection.

Neshta is notable as a classic file infector rather than a modern modular payload family, but it continues to appear in contemporary intrusions as both a persistence mechanism and a delivery vehicle for other malware. It has been observed alongside ransomware and other crimeware operations, including use as a dropper for HardBit 4.0, presence in Vice Society-related incidents, and deployment in phishing-driven campaigns attributed to Red Akodon. It has also appeared in infrastructure associated with other malware operations. Although not regarded as especially advanced in terms of polymorphism or metamorphism, Neshta remains operationally relevant because its infection method complicates cleanup and can facilitate execution of secondary malicious payloads across Windows environments.

Capabilities

  • Defense Evasion
  • Lateral Movement
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 23, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
4 IP / 4 hostnames

Leading locations

  • DE4
  • US2
  • GB1
  • SE1

Leading providers

  • FEMO IT SOLUTIONS LIMITED3
  • Amazon.com, Inc.1
  • Cloudflare, Inc.1
  • Enix Ltd1
  • euNetworks GmbH1
  • Yelles AB1

Infrastructure traits

  • Hosting 8
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Red Akodon

...artifacts... contain the Neshta malware. This malware aims to modify sections of an executable file and load malicious code.

Exploited software

Vulnerabilities linked to Neshta

1 CVEs

MITRE ATT&CK

Neshta in ATT&CK

18 distinct techniques

Reporting

Research mentioning Neshta

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

Jun 22
Squiblydoo

Using the Cert Graveyard - Squiblydoo.blog

Apr 1
Squiblydoo

The CertGraveyard - Squiblydoo.blog

Mar 25
Github Web

GitHub - Squiblydoo/certReport: A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report. · GitHub

Sep 9
Squiblydoo

Quick abuse reports with certReport - Squiblydoo.blog

May 13
Squiblydoo

Impostor Certificates - Squiblydoo.blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.