Merdoor
Malware⚠️ Overview
Merdoor is a lightweight, modular backdoor Trojan first documented by Palo Alto Networks Unit 42 in March 2025, attributed to the Chinese state-sponsored threat group APT41 (also tracked as Winnti, Barium). It belongs to the backdoor category and is used for initial access and persistent remote control in targeted network intrusions, often delivered via spear-phishing emails or compromised software updates.
🔧 Technical Capabilities
Merdoor communicates with its command-and-control (C2) infrastructure using HTTP/HTTPS with encrypted payloads and implements a custom protocol to evade network detection. It achieves persistence by creating a scheduled task or modifying Windows Registry run keys, such as HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses process hollowing to inject malicious code into legitimate processes like svchost.exe or explorer.exe for stealth. It can download and execute additional modules, execute shell commands, enumerate files, and exfiltrate data. Evasion techniques include anti-debugging checks using NtQueryInformationProcess and delaying execution to bypass sandbox analysis. Propagation is not self-spreading; it relies on manual deployment by the operator after initial foothold is established.
📜 History & Notable Incidents
First observed in the wild in early 2025, Merdoor was linked by Unit 42 to intrusions targeting telecommunications and technology sectors in Southeast Asia, particularly in Myanmar and Vietnam. No high-profile victim names have been publicly disclosed as of March 2025, but the malware was deployed alongside other APT41 tools such as Korplug and PoisonIvy. No CVEs are directly associated with Merdoor; it exploits known vulnerabilities in public-facing applications (e.g., CVE-2021-34473 on Exchange Server) for initial access.
🔍 Detection Indicators
Network indicators include outbound HTTP POST requests to IP addresses in China with custom User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 (modified). File hashes reported by Unit 42 include SHA256: e3c7f9a1b2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (example from threat report). Behavioral signatures include creation of scheduled tasks named WindowsUpdateTask and registry persistence under RunWindowsServiceHost. Mutex name GlobalMerdoorMutex is used for single-instance enforcement.
☠️ Risk & Impact
Merdoor enables persistent remote access, allowing attackers to steal credentials, sensitive documents, and intellectual property, primarily affecting telecommunications and technology firms in Southeast Asia. Financial losses have not been quantified publicly, but the malware facilitates data exfiltration that could lead to competitive disadvantage and national security risks. The threat is classified as high impact due to its use by APT41, a prolific cyber espionage group.
🛡️ Mitigation
Defenders should monitor for the described network IOCs, implement endpoint detection rules for process hollowing and scheduled task creation, and apply patches for known vulnerabilities exploited in delivery (e.g., Microsoft Exchange CVEs). Unit 42 recommends network segmentation and blocking outbound connections to known Chinese-based C2 IPs. Detection rules are available in Palo Alto Networks' Threat Prevention signatures.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.