Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 2 hostnames
Neshta is a long-standing Windows file-infector virus, described in the content as active since 2003.
Profile source: Mallory opens in a new tabNeshta
Neshta is a long-standing Windows file-infector virus, described in the content as active since 2003. Its core behavior is to infect executable files by modifying sections of PE files and loading malicious code, and it establishes persistence by hijacking executable launch behavior through the registry, specifically HKLM\SOFTWARE\Classes\exefile\shell\open\command, with observed values such as %SystemRoot%\svchost.com "%1" %*. In observed intrusions, Neshta was stored as C:\Windows\svchost.com, copied itself as a hidden file, and caused original executables to be copied to temporary locations while ensuring code execution whenever EXE files are opened.
The malware appears in multiple operational contexts as both a standalone file infector and as a delivery/persistence mechanism for other malware. It was repeatedly observed alongside Vice Society ransomware activity, where Trend Micro noted the presence of the Neshta file infector during many detections, although the exact introduction vector was unclear. In a Windows cryptomining intrusion, a self-extracting archive (sqlsupdater.sfx.exe) appeared to include Neshta for persistence, alongside NSSM-managed services and scheduled tasks, supporting deployment of an XMRig-based Monero miner. In SCILabs reporting on the Red Akodon threat actor, Neshta was used in phishing-driven campaigns targeting Colombia, where it infected executables and established execution-on-EXE-launch behavior as part of a broader infection chain involving AsyncRAT, RemcosRAT, QuasarRAT, and XWorm. Picus Security also reported that HardBit 4.0 ransomware distribution relied on Neshta as a dropper mechanism: Neshta extracted, decrypted, and launched the HardBit payload from memory offsets while also modifying registry keys for persistence.
Associated actors and malware ecosystems mentioned in the content include Vice Society, Red Akodon, HardBit 4.0 operators, and MuddyWater, whose toolset listing also included the Neshta virus. Targeting reflected the campaigns in which Neshta was embedded rather than a single intrinsic victimology: manufacturing, education, healthcare, and virtualized environments in Vice Society cases; Colombian users and organizations, especially government/judicial-themed phishing victims, in Red Akodon campaigns; and victims exposed via brute-forced RDP/SMB in HardBit 4.0 operations.
High-confidence indicators and artifacts directly mentioned include the registry persistence path HKLM\SOFTWARE\Classes\exefile\shell\open\command, the persistence value %SystemRoot%\svchost.com "%1" %*, the file path C:\Windows\svchost.com, and the sqlsupdater.sfx.exe archive observed in the cryptomining case. Overall, the content characterizes Neshta as a legacy file-infector repurposed in modern operations for persistence and as a dropper or enabler for ransomware, RAT, and cryptomining payloads.
C2 tracking
Derp observations, rolling seven-day window
Samples
2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 72e3991cd84a1d1d798dcf39b1654156a73d844464a7f39962170733e062333e 568889982830c92b84e45978d9a52844cddd900ba87f96513a83592ee7bd2214 76e12fd14798159ab96339a9b01368fa8dfe580648008950eb49dae4ea0096e9 cb2c7098596fd7940d445c64dbf613d6fdb13d6cd638be49121ef79baa0ac844 40218f03e270ec3f93e2d03497341ebd1c2075cb101f1ab4d51c1bd363c2a0aa Reported operators
...artifacts... contain the Neshta malware. This malware aims to modify sections of an executable file and load malicious code.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.