Wild Neutron
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Wild Neutron, also tracked under the aliases Neutron, Morpho and Butterfly, is a hacking group that has been observed targeting major technology companies. The group’s activity was first highlighted in early 2013 when it breached Microsoft’s internal database that tracks unfixed software vulnerabilities. According to former Microsoft employees, the intrusion occurred on or around February 22, 2013 and remained undisclosed to the public. The compromised database contained descriptions of critical and unpatched flaws in widely used software such as the Windows operating system. Open‑source reporting places the group’s known operational base in China, although its exact origins have not been publicly confirmed.
The attackers gained initial entry by exploiting a vulnerability in the Java programming language on employees’ Apple Macintosh computers. From those compromised Macs they moved laterally into corporate networks to reach sensitive systems like the bug‑tracking database. Their tooling appears focused on leveraging known software flaws rather than deploying custom malware families, as no specific malware is referenced in the reporting. The primary objective evident from the Microsoft intrusion was the acquisition of vulnerability information, a type of data valued by state‑sponsored spies and other hackers for follow‑on exploitation. This focus on stealing unpatched flaw details suggests an espionage‑oriented motive rather than financial gain or disruptive intent.
Beyond Microsoft, the same group was reported to have compromised systems at Apple, Facebook and Twitter around the same timeframe, using similar Java‑based techniques. The intrusions remained active after the initial discovery, with security researchers describing Wild Neutron as one of the most proficient and mysterious hacking groups still in operation. Attribution to any nation‑state or criminal consortium has not been established publicly; experts disagree on whether the group is state‑backed and, if so, which government might be involved. Because the group’s tactics rely on exploiting publicly known vulnerabilities and moving through trusted internal networks, it represents a persistent threat to organizations that manage sensitive software‑development data. Organizations are advised to harden Java environments, enforce multi‑factor authentication for critical databases and monitor lateral movement from compromised endpoints to mitigate the risk posed by this actor.
Incidents
Attributed incidents are available to members.
1 incident