New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Research: The Security Tradeoffs Behind AI Tooling
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

Nahash - New Backdoor Targets French Entities with Unique Attack Chain

March 21, 2022

Proofpoint observed new, targeted activity impacting French entities in the construction and government sectors.
The threat actor used macro-enabled Microsoft Word documents to distribute the Chocolatey installer package, an open-source package installer.
Various parts of the VBA macro include ASCII art and depict a snake (Nahash).

The threat actor attempted to install a backdoor on a potential victim's device, which could enable remote administration, command and control (C2), data theft, or deliver other additional payloads.
Proofpoint refers to this backdoor as Serpent (Nahash).
The ultimate objective of the threat actor is currently unknown.