New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

Neptune Loader: Exposing the Hidden Realms of Malware Command And Control / Vulnerability that exposes affected machines

Apr 20, 2025  /  Cypho Research Team  /  3 min read

Introduction

This post talks about a vulnerability that we discovered in Neptune loader. Neptune loader is used for remotely controlling your device, it has some features that help attackers to easily use it. This vulnerability allows us to get information about the affected machines that are called bots. Neptune has a web interface that is used for control. We found a serious vulnerability. The post shares details that can help cybersecurity experts find and fix this weakness.

What is Neptune?

In the threat actor's exact words : "Neptune is an innovative HTTP loader project that provides robust and efficient control over computer systems through commands administered via user-friendly web panel." First seen date is 2023 November 22, user named "M0HX" shared a post on hackerforums.net and promoted a loader named Neptune.

The Neptune loader's advertising page: a native HTTP loader with a C2 web panel, listing features such as a C++ loader, support for many bots and a PHP C2 panel.

During our examination of Neptune loaders, we found something interesting. One of them has a backup file for a database (SQL).

Open directory listing on the C2 server showing neptune.sql, 3.9K, modified 2024-01-12, served by Apache/2.4.58 on 91.92.251.165 port 80.

This file has default usernames and passwords. This discovery gives us important clues about how the loader is set up and might help us understand its security better. As we look into this more, we can learn more about possible issues and weaknesses related to this Neptune loader.

Lines 102 to 106 of neptune.sql: the np_users table with moderator, admin and user accounts and bcrypt password hashes, usernames and hashes redacted.

The passwords were stored as bcrypt hashes. bcrypt is a deliberately slow password-hashing scheme, not encryption, so there is nothing to decrypt: the only way in is to guess candidate passwords and hash each one until one matches. Our team did exactly that and recovered the password.

hashcat output showing a $2y$10$ bcrypt hash with status Cracked, the hash partly redacted.

Upon successfully gaining access to the loaders' dashboard, we conducted a thorough analysis of the application. The objective was to examine every aspect of the system, actively seeking out any potential vulnerabilities that could be exploited. After some time we discovered how our application collects information from the database.

The Neptune panel bot list: infected Windows machines with LAN addresses, computer names and OS versions, identifying values redacted.

We discovered an important security vulnerability within the application, a Broken Access Control (Improper Session Management) issue. This vulnerability exposes a flaw in how the system manages user sessions, enabling unauthorized access to information related to affected machines(Bots). By exploiting this weakness, an unauthorized user gains visibility into sensitive data that should otherwise be restricted.

Captured request and response from the panel API: a POST returning JSON with recordsTotal 21 and infected machine details, identifying values redacted.

The application uses AJAX requests to render a datatable containing the victim's data. A notable vulnerability was identified in the lack of session validation for the endpoint utilized in AJAX requests. This oversight meant that the application did not properly verify the session information, potentially exposing sensitive victim data to unauthorized access or manipulation.

Protecting Against Neptune Loader

Proactive Threat Mitigation: Use proactive measures by utilizing Indicators of Compromise (IoCs) to actively search for potential Neptune Loader infections within your IT environment. This strategic approach involves actively hunting for signs of compromise, allowing for timely detection and mitigation of potential security threats.

Comprehensive Cybersecurity Education: Implement a cybersecurity awareness training program designed to empower employees with the knowledge and skills to recognize and respond effectively to cyberattacks. This educational initiative aims to enhance the overall cybersecurity resilience of the workforce, fostering a proactive and vigilant approach in safeguarding against potential threats posed by malware attacks.

Leverage Advanced Threat Intelligence: Utilize the CYPHO platform, an advanced threat intelligence tool, to enhance your cybersecurity defenses. This platform offers valuable insights and real-time information about emerging threats, enabling your organization to stay ahead of potential risks and bolster its overall security posture.

IOCs

Type Indicator
IP Address 94.156.65.54
Domain mfuk.app
Domain 54.lan-za2-1.static.rozabg.com
Domain tdboat.online
IP Address 91.92.240.161
SHA-256 2a3549512f5f9cf1b11a26897a79532adc548c3000fb7b07fcae6b49cd5222ad

A second SHA-256 in the original version of this post was published incomplete (63 of 64 characters) and has been removed until it can be verified against the sample.


Related reading from Cypho:

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.