Two fresh AlienVault OTX pulses — published October 9–10, 2026 — expose concurrent offensive operations hitting both mobile and developer ecosystems. The first, Mantax Otax, is an Indonesian Android ransomware with fully integrated spyware capabilities, attributed by Zimperium to Indonesian actors and tagged with the ToxicPanda family. The second, NEBULA, is a supply-chain operation that deployed seven malicious npm packages masquerading as a "NebulaAI" SDK to deliver a Windows remote-access trojan (KNTRAT) with HVNC (Hidden Virtual Network Computing) capability.
Neither campaign has confirmed attribution, and both rely on social engineering against high-trust channels — third-party file-sharing platforms for mobile users, and the npm registry for developers. Enterprise teams face a dual-surface problem: personal and BYOD devices used by Indonesian users, and developer workstations or CI/CD pipelines that may have installed poisoned AI SDK packages.
Threat Summary
Pulse 1 — Mantax Otax (Modified 2026-10-10): A mobile threat distributed through third-party file-sharing platforms via social engineering lures. Once installed, the Android payload requests device administrator, SMS, contacts, and accessibility permissions, then encrypts device files using AES. The ransomware component is augmented with spyware: SMS interception, contact exfiltration, and accessibility abuse allow both surveillance and lateral social-engineering propagation. Command-and-control rides on Firebase — Google's legitimate mobile backend infrastructure — which blinds traditional domain-block detection and makes the C2 traffic look like ordinary app telemetry. Over 400 file-hash indicators were published with the pulse.
Pulse 2 — NEBULA (Modified 2026-10-09): In late September 2026, an actor published seven malicious npm packages across four sequential burner accounts (nebulallms through nebulallms4). Packages api-nebula and llm-nebula remained downloadable at publication time. Each package presents a convincing AI client facade while concealing an obfuscated payload that installs KNTRAT, a Windows RAT that "needs no DLL" — implying reflective, fileless, or self-contained injection techniques that reduce on-disk artifacts. HVNC tags indicate the RAT supports hidden desktop sessions for interactive operator access, enabling hands-on-keyboard fraud and credential theft invisible to the legitimate user.
Collective picture: Both operations exploit trusted distribution channels and abuse legitimate infrastructure (npm registry, Firebase) to defeat perimeter controls. The mobile campaign targets end users in Indonesia for financial extortion and data theft; the supply-chain campaign targets developers and, by extension, any organization whose software build chain consumes the tainted packages.
Threat Actor / Malware Profile
Mantax Otax (Android Ransomware + Spyware, ToxicPanda-linked)
- Attribution: Unknown actor; operationally linked to Indonesian threat actors per Zimperium research.
- Distribution: Social engineering via third-party file-sharing platforms; sideloaded APKs.
- Payload behavior: AES file encryption on the device (ransomware), plus SMS harvesting, contact list theft, and surveillance functions (spyware).
- Permissions requested: Device administrator, SMS, contacts, accessibility services — a classic Android abuse quartet enabling persistence, interception, and UI overlay fraud.
- C2 communication: Firebase C2 — leveraging Google's cloud messaging/database infrastructure, which is whitelisted by default in most egress policies.
- Persistence: Device administrator privilege prevents uninstall; accessibility access allows self-protection and permission re-granting.
KNTRAT (Windows RAT, delivered via NEBULA npm packages)
- Attribution: Unknown. Infrastructure includes
api.nebulaai.devand IPv465.87.7.132. - Distribution: Seven typosquatted/impersonating npm packages (
api-nebula,llm-nebula, others) published from burner accountsnebulallms–nebulallms4. A second indicator,fact-register.md, suggests lure or staging content in the package metadata. - Payload behavior: Obfuscated JavaScript in the package delivers a Windows RAT. The "needs no DLL" design indicates in-memory execution or a monolithic PE, minimizing static artifacts.
- C2 communication: HTTPS to
https://api.nebulaai.dev/v2and hard IP65.87.7.132, mimicking legitimate AI API traffic. - Persistence: Not explicitly listed in the pulse; KNTRAT-class RATs typically use Run keys, scheduled tasks, or service installation — hunt accordingly.
- Capabilities: HVNC hidden-desktop sessions for covert interactive access; likely credential harvesting and screen capture.
IOC Analysis
Indicator types present:
| Type | Count | Examples | Operationalization |
|---|---|---|---|
| FileHash-MD5/SHA1/SHA256 | ~402 | 83df0b5583e5f5a282bc0987e220166f0367288b069146ae7d44f4a2d4b21d22 | Bulk-load into EDR blocklists and VirusTotal Enterprise retrohunts. SHA256 is the primary pivot; MD5/SHA1 are legacy duplicates of the same samples. |
| IPv4 | 1 | 65.87.7.132 | Block at firewall/proxy; add to threat intel platform watchlist with 90-day TTL. Retro-search NetFlow/proxy logs for 30 days. |
| Hostname/Domain | 2 | api.nebulaai.dev, fact-register.md | DNS sinkhole/block. Hunt DNS query logs across all endpoints and CI runners. Note fact-register.md may be a lure document name — hunt for it in npm cache and download artifacts. |
| URL | 1 | https://api.nebulaai.dev/v2 | Proxy block; hunt web logs for the full path — the /v2 path narrows false positives versus domain-only matching. |
Firebase C2 caveat: Mantax Otax's C2 is not directly enumerable in the IOC set because it rides on legitimate Firebase domains. Detection must shift to behavior: APKs requesting the admin+SMS+accessibility permission combination, and unexpected Firebase traffic from non-whitelisted apps.
Tooling: Ingest the pulse via the OTX DirectConnect API into your TIP (OpenCTI, MISP, ThreatConnect). Use otx pulsedump or the AlienVault SDK to export indicators to STIX/CSV. For hash triage, cross-reference against MalwareBazaar and VT; for the npm packages, audit package-lock.json / yarn.lock files across repositories for nebula-prefixed dependencies.
Detection Engineering
---
title: NEBULA Malicious npm Package Install Spawning Windows Payload
id: 8f3a2b11-4c6e-4d2a-9b5e-1a7c9e2f3d01
status: experimental
description: Detects node/npm processes spawning script interpreters or executables consistent with KNTRAT delivery from malicious NebulaAI npm packages (api-nebula, llm-nebula).
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.cmd'
- '\npm.exe'
- '\cmd.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
filter_npm_scripts:
CommandLine|contains:
- 'npm run'
- 'npm test'
condition: selection_parent and selection_child and not filter_npm_scripts
falsepositives:
- Legitimate npm install scripts invoking build tooling
level: high
tags:
- attack.initial_access
- attack.t1195.002
- attack.execution
---
title: KNTRAT C2 Communication to NebulaAI Infrastructure
id: 2b7d4c55-9e1f-4a3b-8c6d-5f2a8b1e4d02
status: experimental
description: Detects network connections to KNTRAT command-and-control infrastructure identified in OTX NEBULA pulse.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf
logsource:
category: network_connection
product: windows
detection:
selection_domain:
DestinationHostname|contains:
- 'nebulaai.dev'
selection_ip:
DestinationIp:
- '65.87.7.132'
condition: selection_domain or selection_ip
falsepositives:
- None expected; domain is actor-controlled
level: critical
tags:
- attack.command_and_control
- attack.t1071.001
---
title: Android Ransomware Permission Abuse Pattern - Mantax Otax
id: 5c1e8f33-7a2d-4b4c-9d8e-3f6a1b2c5d03
status: experimental
description: Detects installation of APKs requesting the device administrator, SMS, contacts, and accessibility permission combination characteristic of Mantax Otax mobile ransomware. Deploy via MDM/mobile EDR telemetry forwarded to SIEM.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
logsource:
product: android
service: package_install
detection:
selection_permissions:
RequestedPermissions|contains|all:
- 'android.permission.BIND_DEVICE_ADMIN'
- 'android.permission.READ_SMS'
- 'android.permission.READ_CONTACTS'
- 'android.permission.BIND_ACCESSIBILITY_SERVICE'
selection_source:
InstallerPackage|not_contains:
- 'com.android.vending'
- 'com.google.android.gms'
condition: selection_permissions and selection_source
falsepositives:
- Legitimate MDM or enterprise security agents sideloaded during enrollment
level: high
tags:
- attack.impact
- attack.t1486
- attack.collection
// NEBULA / KNTRAT hunt: npm installs of malicious NebulaAI packages and C2 egress
let BadPkgs = dynamic(["api-nebula","llm-nebula"]);
let BadInfra = dynamic(["api.nebulaai.dev","65.87.7.132","fact-register.md"]);
union isfuzzy=true
(
DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl has_any (BadInfra) or RemoteIP == "65.87.7.132"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
),
(
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where ProcessCommandLine has_any (BadPkgs)
or (InitiatingProcessFileName in~ ("npm.exe","node.exe","npm.cmd")
and FileName in~ ("powershell.exe","wscript.exe","cscript.exe","mshta.exe","rundll32.exe"))
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
),
(
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FolderPath has "node_modules" and FolderPath has_any (BadPkgs)
or FileName =~ "fact-register.md"
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName
)
| sort by TimeGenerated desc
# NEBULA / KNTRAT IOC Hunt Script — Security Arsenal
# Run elevated on developer workstations, build agents, and CI runners.
$ErrorActionPreference = 'SilentlyContinue'
$findings = @()
Write-Host "[1/5] Checking npm global/local packages for malicious NebulaAI SDK..." -ForegroundColor Cyan
$badPkgs = @('api-nebula','llm-nebula')
foreach ($pkg in $badPkgs) {
$installed = npm ls -g $pkg 2>$null
if ($installed -match $pkg) {
$findings += [PSCustomObject]@{Type='npm-global'; Indicator=$pkg; Detail=$installed}
}
}
# Scan node_modules trees in common dev roots
$roots = @("$env:USERPROFILE\source","$env:USERPROFILE\repos","$env:USERPROFILE\projects","C:\agent\_work","C:\build")
foreach ($root in $roots) {
if (Test-Path $root) {
Get-ChildItem -Path $root -Recurse -Depth 6 -Directory -Filter 'node_modules' |
ForEach-Object {
Get-ChildItem $_.FullName -Directory | Where-Object { $_.Name -match 'nebula' } |
ForEach-Object { $findings += [PSCustomObject]@{Type='node_modules'; Indicator=$_.Name; Detail=$_.FullName} }
}
}
}
Write-Host "[2/5] Checking known KNTRAT file hashes..." -ForegroundColor Cyan
$badHashes = @(
'5222dd57b8859e791a16abcf7f616bbc59f8cf248798c7c8c2ba800f0b52cd8c',
'8bc90df9b387849338d9c61a8d379cfbb0d70ea576c0e37e1fb07ba164921807',
'e99bab7b8bbbde7c821dae4ccfedfd1e608d65c466de9b08037c5ce5f56af3b1',
'f0d36ac2d75c81a4c3cbdbf2f717db858f2876e6a1cc74f2d36b729a1dd51a5e'
)
foreach ($root in $roots) {
if (Test-Path $root) {
Get-ChildItem -Path $root -Recurse -File -Include *.exe,*.js,*.dll |
ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
if ($badHashes -contains $h) {
$findings += [PSCustomObject]@{Type='hash-match'; Indicator=$h; Detail=$_.FullName}
}
}
}
}
Write-Host "[3/5] Checking active network connections to KNTRAT C2..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established | Where-Object {
$_.RemoteAddress -eq '65.87.7.132'
} | ForEach-Object {
$proc = Get-Process -Id $_.OwningProcess
$findings += [PSCustomObject]@{Type='c2-connection'; Indicator=$_.RemoteAddress; Detail="PID $($_.OwningProcess) - $($proc.ProcessName)"}
}
Write-Host "[4/5] Checking DNS cache for nebulaai.dev resolution..." -ForegroundColor Cyan
Get-DnsClientCache | Where-Object { $_.Entry -match 'nebulaai\.dev' } |
ForEach-Object { $findings += [PSCustomObject]@{Type='dns-cache'; Indicator=$_.Entry; Detail=$_.Data} }
Write-Host "[5/5] Checking persistence locations for suspicious node/npm-launched entries..." -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
Get-ItemProperty $key | Get-Member -MemberType NoteProperty | ForEach-Object {
$val = (Get-ItemProperty $key -Name $_.Name).$($_.Name)
if ($val -match 'node|npm|nebula') {
$findings += [PSCustomObject]@{Type='persistence'; Indicator=$_.Name; Detail="$key = $val"}
}
}
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'node|npm' } |
ForEach-Object { $findings += [PSCustomObject]@{Type='scheduled-task'; Indicator=$_.TaskName; Detail=$_.Actions.Execute} }
Write-Host "`n===== HUNT RESULTS =====" -ForegroundColor Yellow
if ($findings.Count -gt 0) {
$findings | Format-Table -AutoSize
$findings | Export-Csv -Path ".\nebular_kntrat_hunt_$(Get-Date -Format 'yyyyMMdd_HHmm').csv" -NoTypeInformation
Write-Host "[!] $($findings.Count) findings exported to CSV. Escalate to IR immediately." -ForegroundColor Red
} else {
Write-Host "[+] No KNTRAT/NEBULA indicators found on this host." -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours):
- Block
api.nebulaai.dev,65.87.7.132, andhttps://api.nebulaai.dev/v2at DNS, proxy, and firewall layers. - Bulk-ingest all 402 Mantax Otax hashes and 4 KNTRAT SHA256 hashes into EDR blocklists.
- Audit all npm registries, lockfiles, and CI caches for
api-nebula,llm-nebula, and any package published bynebulallms–nebulallms4. Pin and remove if present. - Search proxy/DNS logs for the last 30 days for connections to KNTRAT infrastructure — any hit is a confirmed compromise, not a lead.
- Via MDM, inventory Android devices with sideloaded apps holding the admin+SMS+accessibility permission trio; isolate Indonesian-user BYOD devices showing the combination.
24 hours:
- KNTRAT's HVNC capability means interactive sessions may have harvested credentials: force password resets and revoke sessions/tokens for any developer or service account on a host that installed the malicious packages. Rotate npm tokens, cloud keys, and SSH keys accessible from those machines.
- For Mantax Otax infections, assume SMS 2FA codes and contacts were exfiltrated — reset credentials protected by SMS-based MFA and notify affected users of possible follow-on social engineering against their contact lists.
- Verify no internal projects depend transitively on the malicious packages; rebuild artifacts produced during the exposure window.
1 week:
- Enforce private npm registry proxying (Verdaccio/Nexus/Artifactory) with package-age quarantine — block packages younger than 14 days and block newly created publisher accounts by default.
- Deploy the Sigma rules above fleet-wide and onboard Android MDM telemetry into the SIEM for the permission-abuse detection.
- Restrict Firebase egress to an application allowlist on managed mobile devices; alert on Firebase traffic from non-approved apps.
- Update developer security awareness: burner-account SDK packages impersonating AI tooling are an active lure theme.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.