Nevereg malware family
Nevereg is a malware family tracked by MalwareAnalyzer by Cyble across 14 publicly analyzed samples. First seen 2026-08-07, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 14
- First seen: 2026-08-07
- Last seen: 2026-08-23
- Verdicts: malicious 14
- File types: pe 14
ATT&CK techniques used by Nevereg
- T1112 - 2 samples
Recent Nevereg samples
- 4b4af0c83f3c3e54e61afda0703eb5dcef5bf09fc733412e7b00661cd8d8fce1 - malicious (2026-08-23)
- 6f402e8f8246b2a0fb7de294cb5745667d11803a20a086c8a987b52497c41fa0 - malicious (2026-08-23)
- 050bdf896fad4c55fdcd46f77a3e46f8320a00871a5ec07e2866395ab168691b - malicious (2026-08-23)
- da091e1d0461ac349d516e478da643f08c90ad3eb7d85eeed36142b08c261be4 - malicious (2026-08-23)
- b73d35cbd95c2636b3b24b04c2c2241524676e9820eb5237cdfb879bc164b79e - malicious (2026-08-22)
- 29923cbb675ccded96d83079b5a737fc1cd985142451bc0800370ad86caa2f8c - malicious (2026-08-22)
- 2935b4667ea1032d4280d167575470ddbb804aa04d58a0aff3033602dfbe6c25 - malicious (2026-08-20)
- 6e3d80a6c9494985f551ffa6361639c14ef254c1201e33e864227667b85363a3 - malicious (2026-08-19)
- 1de522ccad1fc68596c66c1d6960b596b9a6136b3f3d28f588327b50633e13a2 - malicious (2026-08-16)
- 66c1de5267887d8b2e59e302f670f8a2622dd501e2011b4ee57b2e538008f553 - malicious (2026-08-15)
- e91a89079cc34cbcc9090f5e3ca4ec0c9652617240aa5c5208f59aebd48da14d - malicious (2026-08-12)
- 77ee8f861d46d2b7a643d201784254ff73eba64f2b1b0a07c35b0b950510133a - malicious (2026-08-12)
- 1610b6f6e3165d82b0c1ccb4693922e5b680935246b178ad78d854a4f99c5454 - malicious (2026-08-09)
- cc31203ff6f3699b5dd82010f3b7088b171bc2290dff0cb8d9533a4e654a0e48 - malicious (2026-08-07)
Frequently asked about Nevereg
- What is Nevereg?
- Nevereg is a malware family tracked by MalwareAnalyzer by Cyble across 14 publicly analyzed samples. First seen 2026-08-07, most recently 2026-08-23. Observed ATT&CK techniques include T1112.
- How many Nevereg samples have been analyzed?
- MalwareAnalyzer by Cyble holds 14 publicly analyzed samples attributed to Nevereg, first seen 2026-08-07 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Nevereg use?
- Across our Nevereg samples the most frequently observed techniques are T1112 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Nevereg use?
- Nevereg samples in this corpus are distributed as pe (14).
- Is Nevereg malicious?
- 14 of 14 analyzed Nevereg samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends