Skip to main content
Mallory
MalwareUsed by 4 actors

CrowDoor

CrowDoor is a Windows backdoor malware family and a variant of SparrowDoor. It has been used in China-nexus intrusion activity and is associated in the provided reporting with Earth Estries, Salt Typhoon, UAT-9244, and UAT-8302-linked tooling chains; Cisco Talos also describes TernDoor as a CrowDoor variant and notes Draculoader is used to deliver CrowDoor. Reported targeting includes telecommunications infrastructure in South America and broader government and technology victims in activity attributed to China-linked clusters.

Based on the supplied content, CrowDoor supports multiple execution modes depending on a command-line argument. When run with no argument or with argument 0, it sets persistence via a Windows Registry Run key or a service and restarts itself. With argument 1, it restarts by injecting into msiexec.exe. With argument 2, it invokes the main backdoor function. The newer variant differs from older variants by using msiexec.exe as the injected process and by changing command/function IDs.

Capabilities directly described in the content include establishing an initial C2 connection, collecting host information such as computer name, username, OS version, and host/IP information, providing a remote shell, deleting malware files, removing persistence and exiting, and performing file operations including open/read, open/write, drive enumeration, file search, directory creation, rename, and delete. The malware also includes explicit functionality for communication with a command-and-control server.

Persistence mechanisms explicitly mentioned include Registry Run key modification and Windows service creation. The content also states CrowDoor uses process injection into legitimate processes such as msiexec.exe via CreateRemoteThread or NtCreateThreadEx. Reported package combinations associated with CrowDoor include WinStore.exe with Sqlite3.dll, K7Sysmon.exe with K7Sysmn1.dll/K7Sysmn2.dll/K7Sysmn3.dll, HxTsk.exe with d3d8.dll, and MsMsRng.exe with sqlite3.dll and msimg32.dll; some components are described as stored encrypted.

In the supplied reporting, CrowDoor is discussed in operations involving lateral movement and collection activity by Earth Estries, including use alongside PSExec, WMIC, CAB-packaged payloads, batch scripts, Cobalt Strike, and credential theft tooling such as TrillClient. One report also states Salt Typhoon used CrowDoor for persistence through a combination of registry modifications and service creation.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Salt Typhoon

"Crowdoor will perform different actions based on the corresponding argument... Persistence is set through the registry Run key or a service... The backdoor is restarted by injecting to 'msiexec.exe'... Remote shell... File related Operation... Communication with C&C server"

via trend micro research uktrendmicro.com
UAT-9244

A variant of Crowdoor (itself a variant of SparrowDoor), the backdoor is said to have been put to use by UAT-9244 since at least November 2024.

via the hacker newsthehackernews.com
Famous Sparrow

TernDoor is a variant of CrowDoor, a backdoor deployed in recent intrusions linked to China-nexus APTs such as FamousSparrow and Earth Estries. CrowDoor is a variant of SparrowDoor...

via talos intelligence blogblog.talosintelligence.com
Tropic Trooper

TernDoor is a variant of CrowDoor, a backdoor deployed in recent intrusions linked to China-nexus APTs such as FamousSparrow and Earth Estries. CrowDoor is a variant of SparrowDoor...

via talos intelligence blogblog.talosintelligence.com
MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1047Windows Management InstrumentationEvidence1
TacticExecution

"However, in some instances, WMIC may be used in its place to achieve similar results."

T1059.003Windows Command ShellEvidence1
TacticExecution

"A set of batch files will then be copied and executed to perform the extraction, installation, and execution of the malware."

Persistence

2 techniques
T1543.003Windows ServiceEvidence1

"Persistence is set through the registry Run key or a service and the backdoor is restarted"

T1547.001Registry Run Keys / Startup FolderEvidence1

"Persistence is set through the registry Run key or a service and the backdoor is restarted"

T1055Process InjectionEvidence2

"The backdoor is restarted by injecting to 'msiexec.exe'"

T1543.003Windows ServiceEvidence1

"Persistence is set through the registry Run key or a service and the backdoor is restarted"

T1547.001Registry Run Keys / Startup FolderEvidence1

"Persistence is set through the registry Run key or a service and the backdoor is restarted"

Stealth

1 technique
T1055Process InjectionEvidence2

"The backdoor is restarted by injecting to 'msiexec.exe'"

Discovery

3 techniques
T1018Remote System DiscoveryEvidence1
TacticDiscovery

"In later stages of the attack, the backdoors may be used directly to perform lateral movement."

T1082System Information DiscoveryEvidence1
TacticDiscovery

"Collect ComputerName,Username, OS version and hostnet or IP information"

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

"Search File"

Lateral Movement

1 technique
T1021.002SMB/Windows Admin SharesEvidence1

"Earth Estries uses PSExec to laterally install its backdoors and tools... by copying the CAB files... and a batch file to perform the installation"

Collection

1 technique
T1560Archive Collected DataEvidence1

"archived using the tar command"; "Earth Estries utilizes RAR for collecting information of interest"

T1105Ingress Tool TransferEvidence1

"copying the CAB files containing the backdoors or tools, and a batch file to perform the installation"; "uses wget to download target documents"

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.