CrowDoor is a Windows backdoor associated with China-aligned espionage activity and assessed as a variant of SparrowDoor. It has been observed in intrusions linked to clusters including Earth Estries, Tropic Trooper, FamousSparrow-associated activity, UAT-9244, and reporting that also ties its use to Salt Typhoon-related operations. The malware has been deployed in campaigns targeting government entities and telecommunications organizations, including operations in Southeast Asia, the Middle East, and South America.
CrowDoor is commonly delivered through DLL side-loading chains that abuse legitimate signed or trusted executables to load a malicious DLL, decrypt an embedded or companion payload, and execute the backdoor in memory. Related intrusion chains have also used generic shellcode loaders such as Draculoader to deliver CrowDoor, and some campaigns loaded it as a second-stage payload after earlier compromise through web applications or server exploitation. Observed tradecraft places CrowDoor primarily in post-compromise operations rather than as a standalone initial infection mechanism.
Functionally, CrowDoor provides remote shell access, system information collection, file-system manipulation, and command-and-control communications. Reported capabilities include enumerating host details, creating processes or running arbitrary commands, reading and writing files, searching directories, enumerating drives, creating or renaming directories and files, and deleting artifacts. Variants support multiple execution modes controlled by command-line arguments, including installation, persistence setup, restart logic, and invocation of the main backdoor routine.
Persistence is established through Windows Registry Run keys or Windows service creation. Multiple reports describe CrowDoor restarting itself by injecting into legitimate processes, with msiexec.exe specifically noted in newer variants. Process injection is used both for execution and stealth. Some variants also remove persistence and delete their own components when instructed. CrowDoor has been observed dropping or launching additional tooling, including Cobalt Strike, and in at least one collaborative intrusion it was used as a delivery path for ShadowPad.
CrowDoor’s code and behavior show substantial overlap with SparrowDoor, including loader shellcode similarities, structural resemblance, and related command logic. Newer derivatives such as TernDoor retain the same lineage while modifying command codes and adding process-control functionality through an embedded driver. Overall, CrowDoor is best characterized as a modular espionage backdoor used in long-dwell intrusions against high-value networks, especially telecommunications and government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the same period, we also observed other compromised hosts within the same organization communicating with the C&C infrastructure associated with the sub-domain of CrowDoor backdoor.
This attack chain was attempting to load the Crowdoor loader, which is half-named after the SparrowDoor backdoor... The malicious samples are called Crowdoor, which, when run, drop CobaltStrike and maintain persistence.
A variant of Crowdoor (itself a variant of SparrowDoor), the backdoor is said to have been put to use by UAT-9244 since at least November 2024.
TernDoor is a variant of CrowDoor, a backdoor deployed in recent intrusions linked to China-nexus APTs such as FamousSparrow and Earth Estries. CrowDoor is a variant of SparrowDoor...
17 distinct techniques documented for this family, organized by ATT&CK tactic.
"However, in some instances, WMIC may be used in its place to achieve similar results."
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2”... The main loading functionality was designed to execute a legitimate msiexec.exe process, then inject the next stage by writing into its remote address space and creating a remote thread to execute it.
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2”... The main loading functionality was designed to execute a legitimate msiexec.exe process, then inject the next stage by writing into its remote address space and creating a remote thread to execute it.
This function implements the main functionality for this loader, decrypting the shellcode for the next stage from a memory buffer inside the datastate.dll file using a variant of the RC4 stream cipher.
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2” and tries to contact a C2 server that is hardcoded in the payload using its configuration (blog.techmersion[.]com on port 443).
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by Earth Estries for persistence and command-and-control. In this incident it was deployed on a vulnerable internal web server and also used as a vector to deploy ShadowPad.
Mentioned as another backdoor with overlapping infrastructure/TTPs in related investigations.
Payload delivered by Draculoader.
Referenced as a related backdoor family (variant lineage: Crowdoor -> SparrowDoor) used for comparison with TernDoor; specific functional details are not provided beyond its relationship/overlap.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.