Samurai is a Windows backdoor associated with the ToddyCat espionage cluster. It has been used alongside tools such as China Chopper to establish and maintain access on compromised enterprise systems, including intrusions involving Microsoft Exchange exploitation. The malware supports modular post-compromise operations, including compiling and executing downloaded modules at runtime, which helps it adapt functionality on victim hosts and reduce static exposure of payloads. Its loader establishes persistence by creating and modifying Windows service and Registry configuration so that the final backdoor is loaded through svchost.exe, and it has also been observed storing staged components in directories chosen to blend with legitimate system software.
Samurai performs host discovery by checking for the presence and version of the .NET Framework and querying Registry data relevant to the runtime environment. For command and control, it uses web-protocol communications and can Base64-encode data before encryption. It also employs defense-evasion measures such as XOR-based obfuscation of API name strings and other obfuscation techniques noted in ATT&CK mappings. A proxy module allows the malware to forward TCP connections to remote hosts, enabling pivoting or concealed communications through the compromised machine.
Available reporting supports classifying Samurai primarily as a backdoor used in targeted espionage operations. It is notable for persistence through Windows services and Registry modification, modular runtime extension, and proxying capability rather than for commodity crimeware-style mass distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...mass exploitation of ProxyLogon... attackers exploited a ProxyLogon vulnerability to compromise Exchange Servers... used the infamous ProxyLogon exploit to compromise Exchange servers and deploy a China Chopper web shell...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
Samurai ... Obfuscated Files or Information: Dynamic API Resolution
Ninja ... Obfuscated Files or Information: Compression; ... Samurai ... Obfuscated Files or Information: Compression
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
"Aria-body has the ability to use a reverse SOCKS proxy module." / "BADHATCH can use SOCKS4 and SOCKS5 proxies..." / "Neo-reGeorg... establish a SOCKS5 proxy" / "Remcos uses the infected hosts as SOCKS5 proxies"
Cobalt Strike ... Non-Application Layer Protocol; ... Ninja ... Non-Application Layer Protocol; ... Samurai ... Non-Application Layer Protocol
China Chopper ... Ingress Tool Transfer; ... Cobalt Strike ... Ingress Tool Transfer; ... Samurai ... Ingress Tool Transfer
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used to maintain persistent access to compromised systems, allowing remote control and further exploitation.
Samurai is a tool used by ToddyCat to retain access to compromised systems and facilitate credential and cookie theft from web browsers.
Samurai is a backdoor used by ToddyCat APT for persistent access, leveraging multi-stage loaders and registry modifications to maintain stealthy presence on compromised systems.
Samurai is a modular, passive backdoor developed in C# for .NET, deployed by the ToddyCat APT group. It allows attackers to execute arbitrary C# code, upload and run modules for remote command execution, file exfiltration, proxying, and lateral movement. It is designed for stealth, using HTTPListener on common ports (80/443) and is loaded via a multi-stage infection chain, often persisting via Windows services and registry keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.