Tag
HEAVYGRAM Telegram-based Surveillance Backdoor
1 TTPHEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.
China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin America
1 rule 4 TTPs 1 IOCThe state-sponsored threat actor FamousSparrow is deploying the new modular SparroWocky C++ backdoor against government entities in Latin America using advanced anti-analysis techniques.
SparroWock Backdoor Analysis
2 TTPsSparroWock is a backdoor malware that utilizes custom command-and-control communication mechanisms to execute arbitrary commands on compromised Windows systems, establishing persistence to maintain long-term access.
NightEagle APT Targets Russian Organizations with GhostContainer Backdoor
3 TTPs 1 CVEThe NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.
UNC3569 Exploitation of Sogou Input Method to Deploy GRAYRABBIT Backdoor
1 rule 4 TTPs 1 CVE 6 IOCsUNC3569 exploited a command-line argument injection flaw in Sogou Input Method to trigger an insecure Chromium component and execute the GRAYRABBIT backdoor.
Ted Backdoor Implant in Trojanized HAProxy Binaries
3 TTPs 8 IOCsNorth Korean state-sponsored actors are deploying a sophisticated Linux backdoor named 'ted' by replacing legitimate HAProxy binaries with trojanized versions to intercept web traffic and execute malicious commands.
ValleyRAT Backdoor Distributed via Signed Adware
2 rules 2 TTPs 6 IOCsThe threat actor Silver Fox is distributing the ValleyRAT backdoor disguised as a signed QN Wallpaper adware application to leverage user-applied antivirus exclusions.
Historical Campaign Targeting Centreon IT Monitoring Software
3 TTPsBetween 2017 and 2020, threat actors targeted Centreon environments at IT service providers by deploying the P.A.S. webshell and the Exaramel backdoor.
UAT-10147 Deploys SPECTRE Cross-Platform Backdoor
2 rules 6 TTPs 2 IOCsThe threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.
Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor
3 TTPs 4 IOCsThe threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.
Lightweight Backdoor Uses desktop.ini Whitespace for C2 Configuration
1 TTPA 12 KB Windows backdoor evades traditional detection by storing its command-and-control infrastructure within hidden whitespace characters inside standard desktop.ini configuration files.
HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit
1 rule 3 TTPsThe HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.
Supply Chain Compromise of Fluent Forms Pro via Tampered Update Server
4 TTPs 1 CVEFluent Forms Pro 6.2.7 was compromised through a supply chain attack involving a decommissioned update server that served a tampered plugin build, leading to unauthorized backdoor access, persistence, and privilege escalation.
OctLurk and SilkLurk Memory-Resident Backdoors Targeting Central Asia
1 rule 4 TTPs 6 IOCsOctLurk and SilkLurk are sophisticated, memory-resident backdoors targeting government and research entities in Central Asia since January 2025, utilizing machine-specific key derivation for payload decryption and modular plugin injection.
Mirage Kitten Targets Middle East and Africa with New Malware
4 rules 13 TTPs 3 IOCsMirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.
UAC-0145 Uses ClickFix CAPTCHAs to Distribute Data-Stealing Malware
2 rules 9 TTPsRussian state-sponsored threat actor UAC-0145 (Sandworm sub-cluster) is actively targeting Ukrainian organizations by using fake ClickFix CAPTCHAs on compromised websites to trick users into executing malicious PowerShell commands, leading to the deployment of data-stealing malware on Windows and Android devices.
GoSerpent Backdoor and Stowaway RAT Target Government Entities in Southeast Asia for Data Exfiltration
3 rules 9 TTPsAn unnamed threat actor is deploying a sophisticated two-phase attack, utilizing the GoSerpent backdoor, Stowaway RAT, and custom tools like ThumbcacheService and TmcLoader/TmcPayload, to persistently collect sensitive data and credentials from government and diplomatic entities in Southeast Asia for exfiltration.
UAT-7810 Expands ORB Networks with New Malware; ARToken Phishing-as-a-Service and Device Vulnerabilities Highlighted
10 TTPs 8 IOCsThe China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom backdoors like LONGLEASH and DOGLEASH, while other threats include the ARToken Phishing-as-a-Service platform targeting Microsoft 365, critical flaws in AirDrop/Quick Share, and a backdoor in Tenda router firmware.
GigaWiper: Multi-Payload Destructive Backdoor
3 rules 6 TTPs 2 IOCsGigaWiper is a sophisticated, Golang-based destructive backdoor observed since October 2025 by Microsoft Threat Intelligence, that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including physical disk wiping, ransomware-like encryption derived from Crucio, and multi-pass secure wiping reimplemented from FlockWiper.
UAT-7810 Expands ORB Networks with New Custom Malware: LONGLEASH, DOGLEASH, and JARLEASH
1 rule 7 TTPs 4 CVEs 4 IOCsChina-nexus APT actor UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network by exploiting N-day vulnerabilities in Ruckus and ASUS routers to deploy new custom malware families including LONGLEASH, DOGLEASH, and JARLEASH, enabling advanced command and control capabilities for secondary threat actors.
AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content
2 TTPsThis brief details how attackers can leverage compromised AWS credentials to inject malicious, base64-encoded scripts into Amazon SageMaker notebook lifecycle configurations, which then execute as root on notebook instances, enabling persistence, credential theft, or further compromise of the AWS environment.
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
3 rules 1 TTP 8 IOCsOperation FlutterBridge is a malvertising campaign targeting macOS users with the new FlutterShell backdoor, which uses malicious desktop applications for adware distribution and provides backdoor capabilities such as command execution and file system manipulation, with some variants using AI summarization for data exfiltration.
Azure AD User ImmutableId Attribute Modification for Persistence
2 rules 1 TTPThe following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.
SHub Reaper Stealer Backdoors macOS with Multi-Brand Spoofing
3 rules 4 TTPsThe SHub Reaper stealer combines credential theft, wallet hijacking, and document exfiltration with persistent backdoor access on macOS, distributed through fake WeChat and Miro installers while spoofing Apple, Google, and Microsoft to evade detection.
Fake Claude AI Site Spreads Beagle Backdoor via DLL Sideloading
2 rules 2 TTPs 3 IOCsA malicious website impersonating Anthropic's Claude AI platform delivers the Beagle backdoor through a DLL sideloading attack, leveraging a compromised G DATA antivirus updater to execute malicious code.
ScarCruft Compromises Gaming Platform in Supply-Chain Attack
2 rules 4 TTPs 4 IOCsThe ScarCruft APT group conducted a supply-chain attack targeting the Yanbian region by compromising a gaming platform, sqgame, used by ethnic Koreans, trojanizing Windows and Android games with the BirdCall backdoor for espionage activities since late 2024.
Daemon Tools Supply Chain Attack Targeting Government and Scientific Entities
2 rules 1 TTP 3 IOCsA supply chain attack involving trojanized Daemon Tools versions 12.5.0.2421 to 12.5.0.2434 delivered a sophisticated backdoor to a limited number of government, scientific, manufacturing, and retail organizations after a broader initial infection.
Komari Agent Abused as SYSTEM-Level Backdoor
2 rules 4 TTPs 2 IOCsThreat actors are abusing the Komari monitoring agent, a project hosted on GitHub, as a SYSTEM-level backdoor following initial access through compromised VPN credentials and lateral movement via Impacket.
UAT-4356 FIRESTARTER Backdoor Targeting Cisco Firepower Devices
2 rules 2 TTPs 2 CVEs 2 IOCsUAT-4356 is actively targeting Cisco Firepower devices running FXOS, exploiting CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor which allows remote access and control by injecting malicious shellcode into the LINA process.
Malicious Chrome Extensions Stealing Data and Opening Backdoors
2 rules 6 TTPsA coordinated campaign uses 108 malicious Chrome extensions to steal user data, inject ads, and establish backdoors on over 20,000 systems via a shared command-and-control infrastructure.
BPFDoor Lock File Access
2 rules 2 TTPsBPFDoor, an evasive Linux backdoor, is detected via the unusual access of process ID and lock files in the /var/run/ directory, indicating potential malicious activity.
Firefox 0-day Drops OSX.Mokes.B Backdoor on macOS
2 rules 5 TTPs 1 IOCA Firefox 0-day exploit was used to target Mac users, dropping a second backdoor identified as a new variant of the cross-platform Mokes malware (OSX.Mokes.B) with screen capture, audio capture, and document exfiltration capabilities.
Mac Malware Analysis of 2016: KeRanger, Keydnap, and Eleanor
2 rules 1 TTPAnalysis of Mac malware from 2016 including KeRanger ransomware, Keydnap backdoor and credential stealer, and the Eleanor PHP-based backdoor, highlighting their infection vectors and persistence mechanisms.
Comprehensive Analysis of Mac Malware in 2017
3 rules 6 TTPsA comprehensive analysis of Mac malware discovered in 2017, detailing infection vectors, persistence mechanisms, features, and goals, including FruitFly, MacDownloader (iKitten), and others.
Mac Malware of 2018 Retrospective
3 rules 1 TTP 4 IOCsThis brief analyzes Mac malware discovered in 2018, including OSX.Mami, a DNS hijacker distributed via browser popups, and CrossRAT, a cross-platform Java-based backdoor likely spread through phishing, highlighting infection vectors, persistence mechanisms, and capabilities.
Lazarus Group's AppleJeus macOS Backdoor via JMT Trader
2 rules 2 TTPs 3 IOCsThe Lazarus APT group is distributing a macOS backdoor named AppleJeus via a fake cryptocurrency trading application called JMT Trader, persisting through a launch daemon and communicating with the C&C server beastgoc.com.
Detection of ConvertTo-AADIntBackdoor Execution via PowerShell
2 rules 4 TTPsThis brief outlines the detection of the ConvertTo-AADIntBackdoor command execution via PowerShell Script Block Logging, a technique used to create a backdoor in federated Azure AD domains by modifying federation settings and allowing attackers to control the authentication process.
OSX.NetWire.A Backdoor Dropped via Firefox 0-day
3 rules 2 TTPs 4 IOCsA Firefox zero-day exploit was used to target Mac users, resulting in the installation of the OSX.NetWire.A malware, which establishes persistence and communicates with a command and control server.
Compromised WordPress Plugin 'Accordion and Accordion Slider' Delivers Backdoor
2 rules 2 TTPs 1 CVEA malicious actor injected a backdoor into the WordPress 'Accordion and Accordion Slider' plugin version 1.4.6 after purchasing it, allowing for persistence and spam injection.
Azure AD Account Enabled and Password Reset for Backdoor
2 rules 1 TTPDetection of an Azure AD user enabling a disabled account and immediately resetting the password, indicating a potential backdoor being established by an adversary with administrative access.