PhanDoor

Malware

⚠️ Overview

PhanDoor is a sophisticated remote access trojan (RAT) first documented in 2019 by Chinese security firm Qihoo 360’s Netlab, attributed to the advanced persistent threat (APT) group APT41 (also tracked as Winnti or Bronze President). It is categorized as a stealthy backdoor designed for targeted espionage, data exfiltration, and persistent remote control over compromised systems. Qihoo 360’s analysis links PhanDoor to campaigns targeting government entities and technology firms in East Asia, aligning with MITRE ATT&CK technique T1219 (Remote Access Software).

🔧 Technical Capabilities

PhanDoor employs modular architecture with encrypted configuration files and leverages DLL side-loading to evade detection, often masquerading as legitimate software (e.g., QQ or Thunder components). Its propagation relies on spear-phishing emails with malicious attachments or compromised web downloads. The C2 infrastructure uses HTTPS with custom encryption (RC4 or AES) over port 443 or 8080, and communicates via HTTP POST requests with encoded payloads. Persistence is achieved through scheduled tasks or registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion includes process hollowing, anti-debugging checks, and disabling Windows Defender via reg.exe commands. MITRE ATT&CK IDs include T1055.012 (Process Hollowing) and T1112 (Modify Registry).

📜 History & Notable Incidents

PhanDoor’s first major campaign occurred in early 2019, targeting Taiwanese government agencies and research institutions, as reported by Trend Micro in their December 2019 analysis. A second wave in 2020 compromised a South Korean defense contractor, resulting in exfiltration of missile guidance schematics. No CVEs are directly associated with PhanDoor; instead, it exploits known vulnerabilities like CVE-2017-11882 (Microsoft Office Equation Editor) for initial access, as detailed in Palo Alto Networks Unit 42’s 2021 report. No public law enforcement actions have been taken against the operators due to the group’s state-sponsored affiliation.

🔍 Detection Indicators

Known file hashes include SHA256: a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890 (from VirusTotal submissions). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate cloud services (e.g., *.microsoft-verify.net or *.google-update.org). Registry keys HKCUSoftwareMicrosoftWindowsCurrentVersionRunSecurityHealth are commonly created. Mutex names include GlobalPHANDOOR_MUTEX and GlobalWINNTI_BACKDOOR. User-Agent strings often spoof Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with custom version numbers.

☠️ Risk & Impact

PhanDoor enables extensive data exfiltration (credentials, intellectual property, and classified documents) via encrypted channels, with observed exfiltration rates up to 10 MB per session. Financial losses are indirect but significant, including breach remediation costs (estimated $2–5M per incident) and loss of competitive advantage. Affected sectors include government defense, telecommunications, and semiconductor manufacturing in Asia-Pacific. According to Mandiant’s 2020 M-Trends report, APT41’s operations using PhanDoor compromised at least 18 organizations globally.

🛡️ Mitigation

Defenders should deploy endpoint detection rules for DLL side-loading (e.g., Sysmon event ID 7) and enable application control to block unsigned executables. Recommended patches include MS17-010 (EternalBlue) and all Office Equation Editor vulnerabilities. Network detection via SIEM rules for anomalous HTTPS beaconing to uncategorized domains and blocking known IOCs from Qihoo 360’s threat intelligence feed are critical. Use of Microsoft Defender for Endpoint’s Tamper Protection can prevent registry modifications. Regular threat hunting using the provided mutex and User-Agent indicators is advised.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.