EwDoor is a backdoor malware first publicly documented by AT&T Alien Labs in January 2022, attributed to the China-based advanced persistent threat group tracked as APT41 (also known as Winnti or Barium). It primarily targets edge network devices such as VPN appliances and web servers to establish persistent remote access, falling under the categories of Remote Access Trojan (RAT) and botnet payload.
EwDoor gains initial access by exploiting known vulnerabilities in MikroTik routers and F5 BIG-IP appliances, notably CVE-2021-22986 and CVE-2021-22987, as detailed in AT&T Alien Labs research. The malware uses HTTP-based command-and-control (C2) infrastructure encrypted with custom XOR or AES algorithms to exfiltrate data and receive commands. It establishes persistence by modifying system startup scripts or installing cron jobs on Linux-based targets, and can disable security monitoring by terminating competing malware processes. Evasion techniques include dynamic API resolution to avoid import address table hooks and sleeping for randomized intervals to evade sandbox detection.
First observed in late 2021, EwDoor was notably deployed in campaigns targeting telecommunications providers in Southeast Asia, as reported by AT&T Alien Labs in January 2022. A significant incident involved the compromise of F5 BIG-IP appliances at multiple ISPs, where the malware was used to act as a relay for further network intrusions. No law enforcement actions specific to EwDoor have been publicly documented as of early 2024.
Known file hashes include SHA-256 8f7a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (example from AT&T report); behavioral signatures include outbound HTTPS connections to suspicious domains ending in .xyz or .top and creation of files named /tmp/.ewd or /var/tmp/.systemd. Network indicators include User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML) with non-standard parameters.
EwDoor enables full remote control of compromised edge devices, allowing attackers to exfiltrate sensitive configuration data, pivot into internal corporate networks, and deploy additional payloads such as ransomware or credential stealers. The primary impact has been on telecommunications and internet service provider sectors, with potential service disruption and data breach costs exceeding millions of dollars per incident.
Defenders should apply CVEs-2021-22986 and 2021-22987 patches on F5 BIG-IP appliances, monitor for outbound connections to known C2 domains listed in AT&T’s Alien Labs report, and deploy network-based intrusion detection rules (e.g., Suricata signatures) that flag the malware’s unique XOR-encrypted HTTP payloads. Regular firmware updates for MikroTik routers are also critical to prevent initial access.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.