RGDoor is a malicious Microsoft Internet Information Services (IIS) backdoor implemented as a native IIS module in C++. It is designed to provide persistent remote access on compromised Windows web servers by integrating directly into the IIS request-processing pipeline, allowing attacker-controlled HTTP requests to trigger command execution. RGDoor has been associated with Iranian intrusion activity, particularly clusters linked to OilRig/APT34, and has been observed in operations targeting organizations in the Middle East.
The malware supports command execution on the victim server through the Windows command shell and has been documented running discovery commands such as whoami to identify the current execution context. Its communications use HTTP, consistent with its role as an IIS-resident backdoor. RGDoor also includes obfuscation-handling functionality, including Base64 decoding and string decryption using a custom XOR routine.
RGDoor is notable as a persistence mechanism on IIS servers, likely intended to preserve access even if more visible web shells are removed. It has been discussed alongside other IIS malware and web-shell ecosystems used for post-exploitation, credential access, and long-term foothold maintenance on internet-facing enterprise infrastructure. Installation via IIS administrative tooling has also been reported, reinforcing its role as a server-side persistence implant rather than a commodity endpoint payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Known malicious IIS modules: 2013 2018 2019 ... ISN RGDoor
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Appcmd.exe could reportedly be used to install the RGDoor IIS backdoor used by COBALT LYCEUM and COBALT GYPSY.
Appcmd.exe could reportedly be used to install the RGDoor IIS backdoor used by COBALT LYCEUM and COBALT GYPSY.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Multiple malware families and threat groups are described as collecting the victim username or enumerating logged-on users (e.g., “can collect the username from the victim’s machine”, “enumerates the current user during the initial infection”, “enumerates logged-on users”).
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IIS backdoor referenced as relevant to malicious IIS module activity and persistence.
An IIS backdoor used for persistence and malicious access on IIS servers.
An IIS backdoor referenced as a comparison point because its installation technique and tradecraft resemble those used for SheepTransportShell.
Backdoor that executes whoami on the victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.