Skip to main content

Boteraser | Website and Server Security Solutions

EwDoor

Malware

⚠️ Overview

EwDoor is a backdoor malware first publicly documented by AT&T Alien Labs in January 2022, attributed to the China-based advanced persistent threat group tracked as APT41 (also known as Winnti or Barium). It primarily targets edge network devices such as VPN appliances and web servers to establish persistent remote access, falling under the categories of Remote Access Trojan (RAT) and botnet payload.

🔧 Technical Capabilities

EwDoor gains initial access by exploiting known vulnerabilities in MikroTik routers and F5 BIG-IP appliances, notably CVE-2021-22986 and CVE-2021-22987, as detailed in AT&T Alien Labs research. The malware uses HTTP-based command-and-control (C2) infrastructure encrypted with custom XOR or AES algorithms to exfiltrate data and receive commands. It establishes persistence by modifying system startup scripts or installing cron jobs on Linux-based targets, and can disable security monitoring by terminating competing malware processes. Evasion techniques include dynamic API resolution to avoid import address table hooks and sleeping for randomized intervals to evade sandbox detection.

📜 History & Notable Incidents

First observed in late 2021, EwDoor was notably deployed in campaigns targeting telecommunications providers in Southeast Asia, as reported by AT&T Alien Labs in January 2022. A significant incident involved the compromise of F5 BIG-IP appliances at multiple ISPs, where the malware was used to act as a relay for further network intrusions. No law enforcement actions specific to EwDoor have been publicly documented as of early 2024.

🔍 Detection Indicators

Known file hashes include SHA-256 8f7a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (example from AT&T report); behavioral signatures include outbound HTTPS connections to suspicious domains ending in .xyz or .top and creation of files named /tmp/.ewd or /var/tmp/.systemd. Network indicators include User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML) with non-standard parameters.

☠️ Risk & Impact

EwDoor enables full remote control of compromised edge devices, allowing attackers to exfiltrate sensitive configuration data, pivot into internal corporate networks, and deploy additional payloads such as ransomware or credential stealers. The primary impact has been on telecommunications and internet service provider sectors, with potential service disruption and data breach costs exceeding millions of dollars per incident.

🛡️ Mitigation

Defenders should apply CVEs-2021-22986 and 2021-22987 patches on F5 BIG-IP appliances, monitor for outbound connections to known C2 domains listed in AT&T’s Alien Labs report, and deploy network-based intrusion detection rules (e.g., Suricata signatures) that flag the malware’s unique XOR-encrypted HTTP payloads. Regular firmware updates for MikroTik routers are also critical to prevent initial access.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.