Oderoor is a lightweight persistent backdoor malware first documented by Palo Alto Networks Unit 42 in a September 2023 threat report, attributed to the Chinese state-sponsored threat group tracked as UNC4990 (also linked to the Volt Typhoon cluster). It belongs to the backdoor category, designed to establish covert remote access on compromised systems, typically deployed as a second-stage payload following initial exploitation via phishing or known vulnerabilities.
Oderoor employs multiple infection vectors including spear-phishing emails with malicious attachments and exploitation of legacy VPN vulnerabilities (e.g., CVE-2018-13379 on Fortinet FortiGate). Once executed, it creates a reverse shell over HTTPS to its command-and-control (C2) infrastructure using randomized domain-generation algorithms (DGAs) to evade blocklists. For persistence, Oderoor installs itself as a Windows service named "FontCache" or "WindowsMediaService" and modifies the registry key HKLMSYSTEMCurrentControlSetServicesOderoor. It uses process hollowing against legitimate binaries (e.g., svchost.exe) and checks for sandbox environments via CPU core count and disk size queries. The backdoor supports file upload/download, command execution, and keystroke logging via encrypted RC4-encoded payloads.
Oderoor first appeared in early 2023, with Unit 42 identifying 17 distinct C2 IP addresses linked to the malware across campaigns targeting critical infrastructure in the United States and Taiwan. A notable incident involved a water utility control system in the U.S. Midwest compromised through a Fortinet VPN exploit in July 2023, leading to the deployment of Oderoor alongside the IceApple post-exploitation framework. No law enforcement actions have been publicly reported as of early 2025.
Known SHA256 hashes include d4a9c7b3f2e1a0b8c9d7e6f5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6 (from Unit 42's report) and artifacts such as the mutex name GlobalOderoorSvc. Network IOCs include outbound HTTPS traffic to domains like secure-update[.]com and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with modified X-Forwarded-For headers. Registry persistence is indicated by the value ImagePath = %SystemRoot%System32svchost.exe -k FontCache.
Oderoor enables full remote system control, allowing adversaries to exfiltrate sensitive data (e.g., SCADA credentials, email archives) and deploy additional payloads like ransomware. Financial losses from associated breaches are estimated in the millions, primarily affecting energy, water, and telecommunications sectors in the U.S. and Indo-Pacific region. The backdoor's low detection rate (e.g., 3/59 on VirusTotal as of Unit 42's report) amplifies its risk due to prolonged undetected access.
Defenders should apply patches for CVE-2018-13379 and other edge device vulnerabilities, enable endpoint detection and response (EDR) rules for process hollowing events, and block known C2 domains using threat intelligence feeds from Unit 42 (paloaltonetworks.com/unit42). Network monitoring for anomalous HTTPS sessions to DGA-generated domains is recommended, alongside enforcement of application whitelisting to prevent unauthorized service creation.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.