TEMPLEDOOR

Malware

⚠️ Overview

TEMPLEdOOR is a backdoor Trojan associated with the Chinese APT group Elderwood (aka Bisonal, APT12) and was first publicly documented by Kaspersky in 2012. This malware is categorized as a remote access trojan (RAT) and is primarily used for targeted cyber-espionage, allowing attackers to execute commands, steal files, and maintain persistent access to compromised systems.

🔧 Technical Capabilities

TEMPLEdOOR spreads via spear-phishing emails containing malicious Microsoft Office documents that exploit vulnerabilities such as CVE-2012-0158 (Microsoft Office COM component vulnerability) or later CVE-2017-0199. The malware typically arrives as a DLL or executable, using a custom command-and-control (C2) protocol over HTTP or HTTPS with encrypted payloads. It employs a simple XOR-based encryption for network traffic and uses hardcoded C2 domains or IP addresses. Persistence is achieved through Windows Registry Run keys or scheduled tasks. The backdoor can enumerate drives, upload/download files, execute arbitrary commands, and capture screenshots. Evasion techniques include packing with UPX and sleeping to avoid sandbox detection. According to MITRE ATT&CK, this malware maps to techniques like T1071.001 (Web Protocols), T1547.001 (Registry Run Keys), and T1059.003 (Windows Command Shell).

📜 History & Notable Incidents

First observed around 2011, TEMPLEdOOR was used in campaigns targeting defense, aerospace, and government entities in East Asia and the United States. A notable incident was the 2013 attack on Taiwanese shipbuilder CSBS, where TEMPLEdOOR was deployed alongside other tools. In 2020, Cisco Talos reported an updated variant using encrypted C2 payloads. No specific CVEs are assigned directly to the malware itself, but it often exploits CVE-2012-0158 and CVE-2017-0199. Law enforcement actions have not publicly targeted the group operating TEMPLEdOOR.

🔍 Detection Indicators

Known file hashes include MD5: 9f8e7c6d5b4a3c2d1e0f (example; real hashes are documented in Kaspersky and Talos reports). Behavioral signatures include outbound HTTP requests to IPs such as 103.235.46.x or domains ending in `.cn` with User-Agent strings like "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)". The malware creates mutex names such as "GlobalGUID_23456789". Registry modifications include `HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun` with a value named "WindowsUpdate".

☠️ Risk & Impact

TEMPLEdOoor causes data exfiltration of sensitive intellectual property, particularly in the defense and aerospace sectors. Financial losses are indirect but significant due to stolen trade secrets and competitive advantage. The malware has been observed exfiltrating files matching extensions like .doc, .xls, and .pdf. Affected organizations include military contractors and tech firms in Taiwan, South Korea, and the U.S.

🛡️ Mitigation

Recommended defenses include applying patches for CVE-2012-0158 and CVE-2017-0199, using email security gateways to block spear-phishing attachments, and deploying endpoint detection and response (EDR) solutions with signatures for TEMPLEdOOR's C2 traffic patterns. Network defenders should monitor for outbound connections to unfamiliar IPs in China and enforce application whitelisting.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.