Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Nahash - New Backdoor Targets French Entities with Unique Attack Chain

March 21, 2022

Proofpoint observed new, targeted activity impacting French entities in the construction and government sectors.
The threat actor used macro-enabled Microsoft Word documents to distribute the Chocolatey installer package, an open-source package installer.
Various parts of the VBA macro include ASCII art and depict a snake (Nahash).

The threat actor attempted to install a backdoor on a potential victim's device, which could enable remote administration, command and control (C2), data theft, or deliver other additional payloads.
Proofpoint refers to this backdoor as Serpent (Nahash).
The ultimate objective of the threat actor is currently unknown.