HDoor is a Chinese backdoor that has been publicly available since at least 2008. The provided content states that it can kill antivirus software found on a victim system and scan to identify open ports on the victim, indicating both defense-evasion and network reconnaissance functionality. A customized version of HDoor was used in the CL-STA-0045 intrusion cluster targeting a Southeast Asian government from early 2022 through 2023. In that activity, attackers initially exploited Microsoft Exchange Server vulnerabilities, deployed web shells including China Chopper, and attempted to deploy multiple backdoors and tools alongside the customized HDoor. The campaign was attributed with moderate confidence to Alloy Taurus, also known as GALLIUM/Softcell, assessed as operating in support of Chinese state interests. The content also states that HDoor has been used by Chinese APT groups including Growing Taurus (Naikon) and Parched Taurus (Goblin Panda). No HDoor-specific hashes are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The attacker also used a customized version of the Chinese backdoor HDoor."
"The attacker also used a customized version of the Chinese backdoor HDoor."
"The attacker also used a customized version of the Chinese backdoor HDoor."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese backdoor with full remote-control functionality including keylogging, file/process manipulation, scanning, proxying, credential theft, lateral movement support, and data exfiltration.
Backdoor malware that kills antivirus processes on infected hosts.
Backdoor malware that scans victim systems to identify open ports.
Backdoor malware that kills antivirus processes on infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.