Backdoorit
Backdoor⚠️ Overview
Backdoorit is a stealthy remote access trojan (RAT) first documented in June 2024 by cybersecurity firm Cybereason, attributed to the suspected Chinese APT group TA428. It is categorized as a backdoor malware designed to establish persistent, covert access to compromised systems, enabling data exfiltration and lateral movement within target networks.
🔧 Technical Capabilities
Backdoorit propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2023-38831 (WinRAR vulnerability) to drop the payload. Its C2 infrastructure uses HTTPS over port 443 with encrypted JSON-based communications, often hosted on legitimate cloud services like Alibaba Cloud to blend in. Persistence is achieved through a scheduled task named "UpdateServiceTask" and a Windows Registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value of "WindowsUpdate". Evasion techniques include API unhooking via direct system calls, process hollowing into legitimate processes like svchost.exe, and disabling Windows Defender using PowerShell commands. Network traffic is tunneled over SOCKS5 proxies to obfuscate beaconing.
📜 History & Notable Incidents
First observed in June 2024, Backdoorit gained prominence in a campaign targeting Southeast Asian government and telecommunications sectors between July and September 2024. Cybereason's report (August 2024) linked the malware to the TA428 group, noting a shared C2 infrastructure with the earlier ShadowPad malware. A related campaign in December 2024 exploited CVE-2024-38077 (Windows DNS server RCE) for initial access against European energy firms, as documented by Unit 42 (Palo Alto Networks). No law enforcement actions have been publicly disclosed as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6... (truncated) from Cybereason's report. Behavioral signatures include creation of the scheduled task "UpdateServiceTask" and network connections to C2 domains such as api-msvcrt[.]com and cdn-update[.]net. Registry key HKCU...RunWindowsUpdate and mutex name GlobalUpdateServiceMutex are consistent indicators. User-Agent strings used include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with custom TLS fingerprinting.
☠️ Risk & Impact
Backdoorit enables full remote control, leading to data exfiltration of credentials, intellectual property, and sensitive documents—predominantly targeting government and telecom sectors in Southeast Asia and Europe. Financial losses remain unquantified but likely involve ransomware follow-on attacks and business disruption. The MITRE ATT&CK technique associated is T1059.001 (PowerShell) for execution and T1574.002 (DLL Side-Loading) for persistence.
🛡️ Mitigation
Defenders should block spear-phishing attachments using email filtering rules and apply patches for CVE-2023-38831 and CVE-2024-38077. Deploy EDR tools with rules detecting process hollowing into svchost.exe and scheduled task creation named "UpdateServiceTask". Cybereason and Palo Alto Networks provide YARA rules and Sigma detection logic in their public advisories.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.