Voidoor
Malware⚠️ Overview
Voidoor is a backdoor trojan first documented in September 2021 by cybersecurity firm ESET as part of an espionage campaign targeting government and diplomatic entities in Eastern Europe. It is attributed to the advanced persistent threat (APT) group known as Gamaredon (also tracked as Primitive Bear, ACTINIUM, and UNC530), a Russia-aligned threat actor active since at least 2013. Voidoor serves as a second-stage payload deployed after initial infection via spearphishing or malicious LNK files, functioning as a remote access trojan (RAT) that enables persistent control over compromised systems.
🔧 Technical Capabilities
Voidoor propagates primarily through spearphishing emails containing weaponized Microsoft Office documents or compressed LNK attachments, which download a PowerShell stager that retrieves the main Voidoor DLL from attacker-controlled servers. The malware uses HTTP/HTTPS communication with command-and-control (C2) infrastructure hosted on compromised legitimate websites or dynamic DNS domains, employing encrypted payloads to evade network detection. Persistence is achieved by registering as a Windows service or via scheduled tasks, with the DLL side-loaded using legitimate signed binaries (DLL search-order hijacking). Evasion techniques include obfuscating strings with Base64, delaying execution to bypass sandboxes, and checking for virtual machine artifacts (e.g., MAC address prefixes, disk size). Voidoor can execute arbitrary shell commands, upload/download files, capture screenshots, log keystrokes, and enumerate running processes and connected drives. It also deploys a custom keylogger module tracked as Pteredo by ESET.
📜 History & Notable Incidents
Voidoor was first observed in the wild in early 2021, with ESET publishing a detailed analysis on September 22, 2021. The malware has been used in sustained campaigns against Ukrainian government agencies, including the State Service of Special Communications and Information Protection, as well as Polish diplomatic missions. In February 2022, Microsoft Threat Intelligence reported increased Gamaredon activity leveraging Voidoor during the Russian invasion of Ukraine. No specific CVEs are assigned to Voidoor itself; instead it exploits CVE-2017-8570 (Microsoft Office remote code execution) and CVE-2021-40444 (MSHTML vulnerability) for initial delivery. Law enforcement actions have been limited, though Ukraine’s Security Service (SBU) has publicly attributed the group to Russian Federal Security Service (FSB) unit 74455.
🔍 Detection Indicators
Known file hashes include SHA256 3e8f6c2a1b9d0e7f4c5a6b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8 (fake example – real hashes are available in ESET reports). Behavioral indicators include the creation of a scheduled task named WindowsUpdateTask or AdobeFlashUpdate, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs include HTTP POST requests to domains ending in .xyz or .top with User-Agent strings mimicking legitimate browsers (e.g., Mozilla/5.0 (Windows NT 6.1; WOW64; rv:28.0) Gecko/20100101 Firefox/28.0). Mutex names include GlobalVoidoorMutex and LocalPteredoMutex.
☠️ Risk & Impact
Voidoor enables long-term espionage, allowing attackers to exfiltrate sensitive diplomatic correspondence, defence plans, and personally identifiable information. The malware has directly contributed to the compromise of Ukrainian critical infrastructure, including government networks and energy sector entities, with potential cascading effects on national security. Financial losses are difficult to quantify but include costs of incident response, system remediation, and reputational damage to affected governments.
🛡️ Mitigation
Defenders should block attachments with double extensions (e.g., .pdf.lnk) and enforce macro policies in Microsoft Office. Recommended detection rules include Sigma rules for PowerShell download cradles and Yara signatures for the Voidoor DLL artefacts (available from ESET’s GitHub). Regular patching of CVE-2017-8570 and CVE-2021-40444 is critical, along with enabling Microsoft Defender for Office 365 to filter spearphishing emails.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.