NOOPDOOR is a sophisticated backdoor malware associated with recent China-nexus cyber-espionage activity, particularly reporting tied to the broader APT10 ecosystem and Trend Micro’s Earth Kasha / MirrorFace activity targeting Japan, Taiwan, and India. It has been described as an important element of a newer arsenal used for long-duration stealthy persistence in Japanese victim networks, and is also referred to as HiddenFace by ESET.
High-confidence reporting in the provided content describes NOOPDOOR as a complex, fully position-independent backdoor that supports both active C2 polling and passive listening modes. By default it uses a domain generation algorithm (DGA) to change C2 domains daily, is proxy-aware, and communicates over TCP during working time. Its command-and-control traffic is encrypted using RSA together with multiple symmetric ciphers. The malware supports built-in backdoor functions as well as additional modules, including loading encrypted modules from disk for extended functionality.
NOOPDOOR includes substantial evasion and anti-analysis features. Reported characteristics include encrypting and decrypting specific functions at runtime to evade in-memory detection, control-flow obfuscation, junk code, runtime string decoding, and checks for analysis tools that cause the malware to terminate if such tools are found. Delivery in related campaigns has involved DLL side-loading and abuse of digital signature handling associated with MS13-098 / CVE-2013-3900. In the Earth Kasha activity described in the content, NOOPDOOR was used as a persistence mechanism and second-stage backdoor alongside malware such as LODEINFO and Cobalt Strike.
The surrounding campaigns targeted advanced technology, government, manufacturing, aviation, and other strategic sectors, with observed post-compromise activity including credential theft, lateral movement via SMB and scheduled tasks or services, and data exfiltration over backdoor channels or RDP sessions. Related tooling mentioned in the same activity includes NOOPLDR, a loader for NOOPDOOR using advanced encryption and registry-based persistence. No standalone IOC values specific to NOOPDOOR are directly provided in the content beyond its aliases and behavioral characteristics.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybereason’s Cuckoo Spear reporting ties multiple incidents to the APT10 intrusion set and describes long-duration stealthy persistence in Japanese victim networks, with NOOPDOOR and NOOPLDR as important elements of the newer arsenal.
Cybereason’s Cuckoo Spear reporting ties multiple incidents to the APT10 intrusion set and describes long-duration stealthy persistence in Japanese victim networks, with NOOPDOOR and NOOPLDR as important elements of the newer arsenal.
Cybereason’s Cuckoo Spear reporting ties multiple incidents to the APT10 intrusion set and describes long-duration stealthy persistence in Japanese victim networks, with NOOPDOOR and NOOPLDR as important elements of the newer arsenal.
...deliver backdoors known as NOOPDOOR (aka HiddenFace) and ANEL (aka UPPERCUT)...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage backdoor and newer arsenal component in APT10-related reporting, including Japanese victim networks.
Backdoor used by MirrorFace in multi-year cyber-espionage activity targeting Japan (as referenced alongside ANEL).
Backdoor used in MirrorFace spear-phishing campaign targeting Japan.
NOOPDOOR is a highly sophisticated backdoor used by Earth Kasha, supporting both active and passive C2 communication, encrypted with RSA and various symmetric ciphers. It features anti-analysis, in-memory module loading, and a DGA for C2 domain generation. It is typically deployed as a second-stage payload and is used for high-profile targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.