ORPCBackdoor is a custom C++ backdoor first observed in 2022 that communicates with its command-and-control infrastructure over RPC and executes operator-issued instructions on compromised systems. It has been associated with South Asian espionage activity and has been reported in operations linked to Bitter (TA397), Mysterious Elephant (APT-K-47), and Confucius, suggesting either tool sharing, a shared development source, or coordinated use across related clusters.
The malware performs basic host reconnaissance by collecting system details such as username, computer name, operating system information, and running process data. It provides remote access capabilities including shell command execution and file download, enabling follow-on post-compromise activity and sustained operator control. Reporting also describes its use as a long-term remote access implant within broader intrusion chains.
Observed campaigns indicate ORPCBackdoor is typically not the initial infection vector itself, but a later-stage payload delivered after compromise through socially engineered intrusion chains. Associated actors have used spearphishing and exploit-based delivery mechanisms in broader campaigns, including malicious document and CHM-based lures, after which ORPCBackdoor was deployed for persistence and remote tasking. Victimology tied to its use includes government, diplomatic, defense, and other strategic targets in South Asia and beyond, consistent with espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
All three groups have used a custom malware strain known as ORPCBackdoor, suggesting a shared arsenal or possible coordination under a common development entity.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
APT-K-47’s technical and tactical approaches are largely similar to other South Asian groups, primarily revolving around social engineering. Phishing attacks are initiated by delivering bait based on current events... In the 2023 attacks, the organization deployed ORPCBackdoor by sending phishing emails containing malicious CHM attachments.
BDarkRAT includes standard RAT capabilities such as executing shell commands, downloading files, and managing files on the compromised system.
ORPCBackdoor ... initially collects various system details including the username, computer name, operating system, and running processes.
The downloader starts by collecting system information, which includes username, computer name, and the operating system.
Subsequently, they downloaded ORPCBackdoor and other malicious payloads, conducted disk directory traversal, and exfiltrated target files to C2... On another compromised machine, the attacker implants the WalkerShell trojan, which traverses the disk and uploads files of interest to a dedicated file storage server.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RPC-based backdoor for C2 communications and execution of operator-issued commands; also reported by Knownsec 404 as attributed to Mysterious Elephant.
Custom backdoor/remote access malware used by multiple suspected Indian-aligned threat groups, indicating possible shared development or tool-sharing across operations.
ORPCBackdoor is a backdoor used by TA397 and other Indian state-backed threat actors for persistent access and espionage operations.
A C++ backdoor that gathers system and process information, communicates with C2 over RPC, and supports file download and shell command execution. Strings and commands are hex-encoded and decoded at runtime.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.