taidoor

Malware

⚠️ Overview

Taidoor is a remote access trojan (RAT) first documented in 2012 by Trend Micro, attributed to the advanced persistent threat (APT) group APT10 (also known as Stone Panda, Red Apollo, or TA450). It is a custom backdoor used primarily for intelligence gathering against government and defense organizations in Taiwan and other Asia-Pacific entities.

🔧 Technical Capabilities

Taidoor establishes persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and uses HTTP-based command and control (C2) communication with encrypted payloads over port 80 or 443. It utilizes custom encryption, including a XOR-based algorithm with a hardcoded key, to encode C2 traffic and evade network detection. The malware can execute arbitrary commands, upload/download files, capture screenshots, and log keystrokes. It employs process injection into legitimate processes like svchost.exe to blend in with normal system activity. Taidoor also checks for sandbox environments by verifying CPU and disk properties before executing malicious routines.

📜 History & Notable Incidents

First identified in 2012 by Trend Micro during an investigation of targeted attacks against Taiwanese government agencies, Taidoor was linked to a 2014 campaign targeting the Ministry of National Defense of Taiwan. In 2017, it resurfaced in campaigns exploiting CVE-2017-0147 (SMBv1 vulnerability related to EternalBlue) to propagate within networks. The malware has been associated with espionage operations by APT10, which have been documented by MITRE ATT&CK under group G0047.

🔍 Detection Indicators

Known file hashes include SHA256: e4f2b1a3c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (from Trend Micro research). Network IOCs include HTTP GET requests to C2 domains with URI patterns like /admin/images.php?id= and User-Agent strings such as Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1). Registry persistence markers like HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftUpdate are common.

☠️ Risk & Impact

Taidoor poses a high risk due to its stealthy data exfiltration capabilities, targeting classified documents and intellectual property from government and military sectors. The malware has caused significant damage to Taiwanese national security, with campaigns stealing sensitive diplomatic and defense information. Financial losses from stolen data and remediation costs are estimated in the tens of millions of dollars, though exact figures remain classified.

🛡️ Mitigation

Mitigation includes network segmentation, strict egress filtering of HTTP traffic, and deploying endpoint detection and response (EDR) solutions capable of identifying process injection anomalies. Apply patches for CVE-2017-0147 and maintain updated antivirus signatures that detect Taidoor variants. Refer to MITRE ATT&CK technique T1055 for process injection detection guidance and review Trend Micro's 2012 report for detailed defensive measures.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.