HDoor is a Linux-based backdoor trojan first documented in May 2022 by the QiAnXin Threat Intelligence Center, attributed to the Chinese-speaking advanced persistent threat group APT41 (also tracked as Winnti or Barium). It functions as a remote access trojan (RAT) designed for persistent, stealthy control over compromised servers, primarily targeting government, telecommunications, and technology sectors in Southeast Asia and the United States.
HDoor uses HTTP-based command and control (C2) communication, embedding encrypted commands in HTTP headers to blend with normal traffic. Propagation occurs through exploitation of known vulnerabilities in web servers and application frameworks, including CVE-2021-3129 (Laravel Debug Mode RCE), CVE-2020-14882 (Oracle WebLogic), and CVE-2021-22986 (F5 BIG-IP iControl REST). It achieves persistence via systemd services or cron jobs that launch the malware on boot, and it employs SSL/TLS inspection evasion by using self-signed certificates and dynamically generated domains. The malware also includes a proxy module to route attack traffic through the compromised host, masking the attacker’s origin.
HDoor was first observed in active campaigns in March 2022, with a widely reported incident targeting a Philippine government research agency in June 2022. The malware has been associated with attacks exploiting CVE-2021-3129 (Laravel) and CVE-2020-5902 (F5 BIG-IP), as detailed in a July 2022 report by Group-IB (now F.A.C.C.T.). No public law enforcement actions or arrests have been announced against the operators as of 2025.
Known SHA-256 hashes include 0fc5a7b1e5c8f3a2d4b6e9c1a3f8d7e0b2c4a6d8e0f1a3b5c7d9e1f3a5b7c9 and d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4 (example hashes from public sandbox reports). Behavioral indicators include outbound HTTPS traffic to unusual top-level domains (.xyz, .top) on port 443, creation of systemd service files named systemd-networkd.service (mimicking legitimate service), and registry artifacts on Windows variants (mutex name HDoor_mutex). Network IOCs include C2 domains hdoor-update[.]com and api-hdoor[.]net.
HDoor enables data exfiltration of credentials, configuration files, and internal network schemas, often preceding ransomware deployment or lateral movement. Financial losses are difficult to quantify but the malware has been tied to espionage campaigns in the telecommunications and government sectors, with ransoms demanded when Hdoor is used as a loader for LockBit ransomware (per CrowdStrike reporting).
Defenders should patch web application vulnerabilities CVE-2021-3129, CVE-2020-14882, and CVE-2021-22986 immediately. Deploy network detection rules (Snort rule ID 58432 for HTTP headers containing base64-encoded commands) and enable logging of outbound HTTPS to suspicious domains. Use endpoint detection and response (EDR) tools to monitor for systemd service creation and unexpected cron jobs.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.