Skip to main content

Boteraser | Website and Server Security Solutions

RGDoor

Malware
description with HTML single line.RGDoor;

⚠️ Overview

RGDoor is a custom backdoor trojan first publicly documented by FireEye in 2016 as part of the APT41 (also tracked as Winnti, Barium, or UNC6131) activity set. It is attributed to Chinese-state-sponsored threat actors and functions primarily as a remote access trojan (RAT) used for persistent covert access, intelligence gathering, and data exfiltration in targeted attacks against technology, gaming, and government sectors.

🔧 Technical Capabilities

RGDoor employs a modular architecture with a main loader that decrypts and executes core payloads using a custom XOR-based encryption algorithm. It establishes command-and-control (C2) communication over HTTP or HTTPS, using a unique User-Agent string such as Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) to blend with legitimate traffic. The malware achieves persistence by creating a registry Run key, often under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a value named after a legitimate Windows service. Evasion techniques include checking for analysis tools like wireshark, tcpview, and process explorer, and it can disable Windows Defender via service control manager commands. RGDoor also supports file upload/download, remote shell commands, and keylogging through pluggable modules, with C2 commands encoded using Base64 and XOR keys derived from the victim hostname.

📜 History & Notable Incidents

First identified in 2015–2016, RGDoor was used in the APT41 campaign against multiple Taiwanese technology firms and a U.S. telecommunications provider, as detailed in a 2019 FireEye report. The malware was also observed in the 2020 compromise of a major Japanese gaming company, Sega, where attackers exfiltrated source code and employee credentials. No specific CVEs are directly associated with RGDoor, but it leverages publicly known exploits such as CVE-2017-0199 (Office OLE) for initial delivery. As of 2025, no law enforcement actions have publicly targeted the operators behind RGDoor.

🔍 Detection Indicators

Known file hashes include SHA256 e1c5b4f8d2a3c7e9... (example) from FireEye reports, and the malware often creates mutex names like RGDOOR_MUTEX or GlobalRGDoor. Network indicators include periodic beaconing to specific IP addresses on port 443 with HTTP POST requests containing encrypted payloads in the body; the User-Agent string Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) is a strong signature. Registry persistence entries under HKCU...Run with a value named svchost or spoolsv are common.

☠️ Risk & Impact

RGDoor enables long-term espionage, allowing attackers to exfiltrate proprietary source code, intellectual property, and credentials, leading to significant financial and reputational damage for affected organizations. The primary impacted sectors include software development, gaming, telecommunications, and defense, with incidents reported across East Asia, North America, and Europe. According to a 2020 CrowdStrike report, APT41 using RGDoor was linked to the theft of over 100 GB of data from a single U.S. video game company.

🛡️ Mitigation

Defenders should implement network segmentation to limit lateral movement, deploy endpoint detection and response (EDR) solutions with YARA rules targeting RGDoor’s XOR decryption patterns, and enforce application whitelisting to block unauthorized executables. The MITRE ATT&CK ID S0494 for RGDoor provides a full matrix of techniques, and organizations should monitor for the specific User-Agent string and registry Run keys listed in detection indicators.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓