APTMembers
APT

DarkHotel's Decade-Old Nemim Trojan Still Evades Detection in 2026

A 56-kilobyte Windows implant first seen in 2013 remains operationally active against India-region espionage targets, sustained by a layered evasion stack and rotating dynamic-DNS infrastructure. Fresh hosting infrastructure on Bulgarian servers was observed as recently as May 2026, even as the core binary dates to the early Obama era. Seventeen percent of commercial antivirus engines still miss a sample that has been publicly known for over a decade.

Jun 7, 2026, 23:21 (UTC+9)Last seenJun 8, 2026Severity87ByCTX TeamActorDarkHotelFallout TeamIOC12MITRE28RegionsIN

A 56-kilobyte Windows executable first submitted to VirusTotal in February 2013 is still being resubmitted and tracked as an active threat as recently as March 2025 — and the infrastructure supporting it has grown fresher, not older. The implant at the centre of this campaign is Nemim, a multi-role trojan attributed by CTX Team to DarkHotel and directed at espionage targets in India.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence