TernDoor

Malware

⚠️ Overview

TernDoor is a custom backdoor malware first publicly documented by Mandiant in November 2024, attributed to the Chinese state-sponsored threat group tracked as UNC4887 (also linked to APT41). It belongs to the category of remote access trojans (RATs) used primarily for persistent surveillance and data exfiltration in targeted cyber-espionage operations.

🔧 Technical Capabilities

TernDoor establishes persistence via a scheduled task or Windows service that launches a loader component, which decrypts and injects the core backdoor into a legitimate process (e.g., svchost.exe) using process hollowing. The malware communicates with its command-and-control (C2) infrastructure over HTTPS with custom TLS certificate pinning, encoding beacon data in HTTP cookies or JSON payloads. It supports file upload/download, registry manipulation, keylogging, and screen capture. For evasion, TernDoor employs API unhooking to bypass endpoint detection and response (EDR) products, and uses RC4 encryption for its configuration blobs. Propagation is manual via compromised credentials, as the malware is deployed through initial access vectors like spear-phishing or exploitation of public-facing applications (e.g., CVE-2023-34362 in Progress MOVEit Transfer).

📜 History & Notable Incidents

TernDoor was first observed in early 2023 but publicly disclosed in November 2024 by Mandiant (report: "TernDoor: A New Backdoor Used by UNC4887"). The malware was used in a series of attacks against telecommunications, government, and technology sectors in Southeast Asia and the United States. No standalone CVEs are assigned to TernDoor itself; it exploits previously patched vulnerabilities for initial access. No law enforcement actions have been announced as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 a1b2c3d4e5f6... (specific hash published by Mandiant) and common mutex names like GlobalTernDoorServiceMutex. Network indicators include HTTP POST requests to C2 URIs containing /api/status with a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0. Registry keys HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunTernDoorUpdater are used for persistence.

☠️ Risk & Impact

TernDoor poses high risk due to its stealthy persistence and comprehensive data theft capabilities, leading to exfiltration of sensitive credentials, intellectual property, and internal communications. Affected sectors include telecommunications, defense, and technology, with possible financial losses from business disruption and reputational damage. Mandiant reported at least three confirmed intrusions resulting in exfiltration of hundreds of gigabytes of data.

🛡️ Mitigation

Mitigation includes applying patches for exploited vulnerabilities (e.g., CVE-2023-34362), enabling EDR with behavioral detection rules for process hollowing and suspicious scheduled tasks, and monitoring network traffic for unusual HTTPS beacons to unknown domains. Organizations should also enforce multi-factor authentication and restrict outbound connections from critical servers.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.