Nightdoor is a Windows backdoor associated with the China-aligned espionage cluster Evasive Panda, also tracked as Daggerfly and BRONZE HIGHLAND. It has been used in cyberespionage operations targeting organizations and communities of geopolitical interest, including entities in Taiwan and Tibetan-related targets, and has also been linked to activity involving an American NGO in China. The malware has been described as a previously undocumented Windows backdoor within this actor’s toolset.
Nightdoor supports long-term remote access and victim profiling. Reported functionality includes collection of system, user, and network information, including usernames and local system time. It can communicate with operators over TCP and UDP and can also use trusted cloud services such as Microsoft OneDrive or Google Drive for command and control, helping its traffic blend with legitimate activity. Reported command support includes reverse shell access, file operations, and self-uninstall capability.
For persistence, Nightdoor has been observed using Windows scheduled tasks to ensure execution and to load its final payload into memory. It has also been associated with reflective code loading and process injection into svchost.exe, indicating an emphasis on in-memory execution and defense evasion. Reporting also links its deployment to DLL side-loading in broader intrusion chains used by Daggerfly and Evasive Panda.
Nightdoor is part of a broader malware ecosystem used by Daggerfly alongside tools such as MgBot, MacMa, and PlugX-related components. Its tradecraft and targeting are consistent with sustained intelligence collection rather than disruptive or financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among others, this technique has been leveraged by APT41 to deploy DUSTTRAP and Daggerfly to deliver Nightdoor backdoor.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Nightdoor ... (v1.0→v1.1) ...
Nightdoor (v1.0→v1.1)
Nightdoor is a newly identified backdoor malware deployed by the Evasive Panda threat actor, designed to enable covert access and control over victim systems.
Referenced as a backdoor delivered via DLL side-loading in another campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.