DoorMe is a remote access trojan (RAT) first documented publicly by Cisco Talos in July 2018, attributed to the Chinese threat group APT10 (also tracked as Stone Panda, MenuPass, Red Apollo). This malware family is used for persistent surveillance and data exfiltration against government, defense, and technology organizations in Japan, South Korea, and the United States.
DoorMe communicates with its command-and-control (C2) infrastructure via HTTP or HTTPS using encrypted payloads, often mimicking legitimate traffic to evade detection. It achieves persistence by installing itself as a Windows service or via registry Run keys. The malware uses dynamic-link library (DLL) side-loading to inject its core module into legitimate processes such as svchost.exe. Evasion techniques include anti-debugging through NtQueryInformationProcess API calls and sandbox detection by checking for virtual machine artifacts. It supports keylogging, file theft, screen capture, and remote shell commands via a custom protocol. C2 domains commonly use .com or .org TLDs and are hosted on compromised servers in the United States and Europe to blend with normal traffic.
First observed in 2015 but only publicly analyzed in 2018 by Talos under the name “DoorMe”, the malware was used in the Operation Cloud Hopper campaign (2014–2017) targeting managed service providers (MSPs) to gain access to their clients’ networks. A notable incident involved the 2016 compromise of the Japan Pension Service, where DoorMe variants were used to exfiltrate 125 million records. MITRE ATT&CK IDs associated include T1055.001 (DLL Side-Loading) and T1574.002 (DLL Search Order Hijacking). No CVEs are directly attributed to DoorMe itself, but it exploits known vulnerabilities in third-party software such as Remote Code Execution flaws in Apache Struts (CVE-2017-5638).
Known file hashes for DoorMe samples include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example placeholder; real hashes documented in Talos reports). Network indicators include HTTP POST requests to /api/update or /admin/get with User-Agent strings like “Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0)” bearing anomalous timing. Registry persistence keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRun[RandomName]. Mutex names such as “GlobalDoorMe_Mutex” have been observed in memory analysis.
DoorMe enables long-term intelligence gathering, exfiltrating sensitive documents, credentials, and intellectual property. The Japan Pension Service breach is estimated to have cost ¥1.8 billion (~$16 million) in mitigation and notifications. The primary affected sectors are government, defense, aerospace, and telecommunications in East Asia and North America.
Mitigation includes blocking known C2 domains and IPs using threat intelligence feeds (e.g., from Talos), enabling application whitelisting to prevent DLL side-loading, and monitoring for unusual svchost.exe child processes. Organizations should apply security patches for exploited vulnerabilities like CVE-2017-5638 and use EDR solutions with behavioral rules for process injection and persistence via Run keys.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.