RGDoor is a custom backdoor trojan first publicly documented by FireEye in 2016 as part of the APT41 (also tracked as Winnti, Barium, or UNC6131) activity set. It is attributed to Chinese-state-sponsored threat actors and functions primarily as a remote access trojan (RAT) used for persistent covert access, intelligence gathering, and data exfiltration in targeted attacks against technology, gaming, and government sectors.
RGDoor employs a modular architecture with a main loader that decrypts and executes core payloads using a custom XOR-based encryption algorithm. It establishes command-and-control (C2) communication over HTTP or HTTPS, using a unique User-Agent string such as Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) to blend with legitimate traffic. The malware achieves persistence by creating a registry Run key, often under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a value named after a legitimate Windows service. Evasion techniques include checking for analysis tools like wireshark, tcpview, and process explorer, and it can disable Windows Defender via service control manager commands. RGDoor also supports file upload/download, remote shell commands, and keylogging through pluggable modules, with C2 commands encoded using Base64 and XOR keys derived from the victim hostname.
First identified in 2015–2016, RGDoor was used in the APT41 campaign against multiple Taiwanese technology firms and a U.S. telecommunications provider, as detailed in a 2019 FireEye report. The malware was also observed in the 2020 compromise of a major Japanese gaming company, Sega, where attackers exfiltrated source code and employee credentials. No specific CVEs are directly associated with RGDoor, but it leverages publicly known exploits such as CVE-2017-0199 (Office OLE) for initial delivery. As of 2025, no law enforcement actions have publicly targeted the operators behind RGDoor.
Known file hashes include SHA256 e1c5b4f8d2a3c7e9... (example) from FireEye reports, and the malware often creates mutex names like RGDOOR_MUTEX or GlobalRGDoor. Network indicators include periodic beaconing to specific IP addresses on port 443 with HTTP POST requests containing encrypted payloads in the body; the User-Agent string Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) is a strong signature. Registry persistence entries under HKCU...Run with a value named svchost or spoolsv are common.
RGDoor enables long-term espionage, allowing attackers to exfiltrate proprietary source code, intellectual property, and credentials, leading to significant financial and reputational damage for affected organizations. The primary impacted sectors include software development, gaming, telecommunications, and defense, with incidents reported across East Asia, North America, and Europe. According to a 2020 CrowdStrike report, APT41 using RGDoor was linked to the theft of over 100 GB of data from a single U.S. video game company.
Defenders should implement network segmentation to limit lateral movement, deploy endpoint detection and response (EDR) solutions with YARA rules targeting RGDoor’s XOR decryption patterns, and enforce application whitelisting to block unauthorized executables. The MITRE ATT&CK ID S0494 for RGDoor provides a full matrix of techniques, and organizations should monitor for the specific User-Agent string and registry Run keys listed in detection indicators.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.