Government, financial and industrial organizations located in Asia, Africa and Latin America are the targets of a new campaign dubbed PassiveNeuron, according to findings by Kaspersky.
See also: Chinese hackers abuse legal tool Nezha

The cyberespionage activity was first highlighted by the Russian cybersecurity vendor in November 2024, when it uncovered a series of attacks targeting government entities in Latin America and East Asia in June, using previously unseen malware families, such as Neursite and NeuralExecutor.
The operation presents a high level of sophistication, with threat actors leveraging already compromised internal servers as an intermediate command and control (C2) infrastructure to remain undetected. The threat actor is able to move laterally through the infrastructure and extract data, optionally creating virtual networks that allow attackers to steal files of interest even from machines that are isolated from the internet. A plug-in-based approach provides dynamic adaptation to the attacker’s needs.
Since then, the company has observed a new wave of infections related to PassiveNeuron starting in December 2024 and continuing until August 2025. The campaign remains unattributed at this stage, although some signs indicate it is the work of Chinese-speaking threat actors.
In at least one incident, the adversary is said to have gained initial remote command execution capabilities on a compromised machine running Windows Server via Microsoft SQL. While the exact method by which this is achieved is unknown, it is likely that the attackers are either attempting to crack the administrator account password, exploiting an SQL injection in an application running on the server, or exploiting an unspecified vulnerability in the server software itself.
See also: Chinese 'Phantom Taurus' targets organizations with Net-Star

Regardless of the method used, the attackers attempted to deploy an ASPX web shell to gain basic command execution capabilities. Failing in these attempts, the attack followed up by delivering advanced implants via a series of DLL loaders placed in the System32. These include:
– Neursite, a custom C++ modular backdoor
– NeuralExecutor, a custom .NET implant used to receive additional .NET payloads over TCP, HTTP/HTTPS, named pipes, or WebSockets and execute them
– Cobalt Strike, a legitimate adversary simulation tool
Neursite uses a built-in configuration to connect to the C2 server and uses TCP, SSL, HTTP, and HTTPS protocols for communications. By default, it supports the ability to collect system information, manage running processes, and broker traffic through other machines infected with the backdoor to allow lateral movement.
The malware is also equipped with a component to retrieve helper plugins to achieve shell command execution, file system management, and TCP socket operations.
Kaspersky noted that the NeuralExecutor variants observed in 2024 were designed to retrieve C2 server addresses directly from the configuration, while the objects found this year target a GitHub repository to obtain the C2 server address—a technique referred to as the dead drop resolver technique.
See also: Sidewinder APT exploits protests in Nepal to distribute malware

The PassiveNeuron campaign has been distinguished by the way it primarily targets server machines. Servers, especially those exposed to the internet, are typically attractive targets for advanced persistent threats, as they can serve as entry points into targeted organizations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
