cd00r is an open-source passive backdoor for Unix-like systems that waits for specially crafted network traffic rather than exposing a conventional listening service. Originally released around 2000 by the phenoelit group, it is designed for stealth: it uses packet-capture functionality, commonly via libpcap, to monitor inbound traffic for a predefined TCP port-knocking or magic-packet sequence and only then activates follow-on access. Because it does not normally present an open port, it can evade basic network inspection methods that rely on identifying listening services.
The malware’s core behavior is to monitor captured packets for specific sequences and, when triggered, enable attacker control of the compromised host. Variants and derivatives based on cd00r have been observed to establish shell access or otherwise support remote command execution after receipt of the trigger traffic. cd00r has also served as the basis for later Linux backdoors used in real intrusions, including custom variants deployed post-compromise and malware families such as SEASPY. A Linux Turla implant discovered in the wild was described as a stealth backdoor based on cd00r source code that used packet capture to detect magic packets and then connected back to the sender to execute commands.
cd00r is associated primarily with Linux and other Unix-like environments and is notable less as a modern malware family than as a foundational open-source backdoor design that has influenced later passive implants. Its operational value lies in stealthy post-compromise access and defense evasion through covert activation over network traffic rather than overt command-and-control beacons or exposed services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early passive backdoor that waits for a TCP port-knocking sequence.
An open-source backdoor for post-compromise use; the campaign used a custom variant.
Backdoor/tool that leverages libpcap to monitor captured packets and match specific sequences.
An open-source backdoor mentioned only as an initially suspected but incorrect basis for Penquin Turla.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.