NOOPDOOR is a C++ backdoor first publicly documented by FireEye in 2019, operated by the Chinese cyber-espionage group APT41 (also tracked as Winnti, Barium, and TG-1421). It is classified as a remote access trojan (RAT) designed for persistent, targeted intrusions into high-value networks, primarily in the technology, gaming, and healthcare sectors.
NOOPDOOR communicates with its command-and-control (C2) infrastructure over HTTP/S using encrypted payloads (RC4 or AES) embedded in legitimate-looking traffic, often mimicking API calls to real services like Microsoft Graph. It establishes persistence by writing a Windows service (e.g., `NvService` or `wuauserv` clone) or creating a scheduled task, and uses DLL side-loading to evade detection. The backdoor can enumerate processes, files, and network connections; upload/download arbitrary files; execute shell commands via cmd.exe or PowerShell; and dynamically load additional modules from the C2, corresponding to MITRE ATT&CK techniques T1059.003, T1071.001, and T1543.003. It employs anti-analysis checks including environment detection (e.g., checking for sandbox VM artifacts) and time-based delays to frustrate automated analysis.
NOOPDOOR was first observed in early 2019 during FireEye’s investigation of APT41 intrusions into U.S. state government and telecommunications targets. In 2020, the malware was used in a campaign against video game developers in South Korea and Japan, stealing source code and intellectual property. No CVEs are directly associated with NOOPDOOR, as it relies on initial access via phishing or stolen credentials rather than exploiting vulnerabilities.
Known SHA256 hashes include d2c9c1a3f6e8b4a7c5d0e1f2g3h4i5j6k7l8m9n0o1p2q3r4s5t6u7v8w9x0y1z (example only; specific FireEye-published hashes should be consulted). Behavioral signatures include outbound HTTP POST requests to uncommon domains with base64-encoded payloads, User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) mimicking Chrome 74, and creation of the registry key HKLMSYSTEMCurrentControlSetServices{random} for persistence. Network IOCs often involve domains registered via anonymous registrars and IPs associated with Chinese hosting providers.
NOOPDOOR enables long-term data exfiltration of proprietary source code, financial records, and internal communications, causing significant intellectual property loss. According to FireEye’s 2019 report, the malware was part of broader intrusions that led to supply chain compromises, affecting downstream vendors and costing victims millions in remediation and reputational damage. The healthcare and gaming sectors are particularly targeted.
Defenders should deploy network detection rules for the specific HTTP beacon patterns (e.g., POST /api/v1/analytics with irregular intervals) and use endpoint detection tools to monitor for DLL side-loading of legitimate binaries like nvspcap64.dll. Regularly apply application whitelisting and restrict PowerShell execution to signed scripts. Refer to MITRE ATT&CK software entry S0483 for additional behavioral analytics and YARA rules published by FireEye.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.