Samurai is a modular passive C# backdoor associated with the ToddyCat APT, an espionage-focused cluster active since at least December 2020. It was used in attacks against high-profile entities in Europe and Asia, including government, military, defense-related organizations, and initially compromised Microsoft Exchange servers in Taiwan and Vietnam. ToddyCat first deployed it after compromising Exchange via an unknown exploit and later in broader ProxyLogon-related activity.
Samurai typically operates on ports 80 and 443 and uses the .NET HTTPListener class to process specially crafted HTTP POST requests. It allows arbitrary attacker-supplied C# source code to be compiled and executed at runtime. Reported Samurai-uploaded modules support remote command execution, file enumeration, file exfiltration, and proxying/forwarding TCP traffic. The malware has been used to communicate with internal IPs over ports including 135, 445, 389, 80, and 443 for lateral movement, and in some cases was used to deploy the Ninja post-exploitation tool.
Its configuration is base64-encoded and DES-encrypted with a hardcoded key 90 EE 0C E1 6C 0D C9 0C, and is customized per victim. Configuration can include URI prefixes such as /owa/auth/sslauth/ and victim-domain-specific URL prefixes. On successful execution, Samurai returns HTTP 200 responses containing AES-encrypted, base64-encoded output.
The documented installation chain used a dropper (debug.exe), a C++ DLL loader (iiswmi.dll), and a C# .NET loader (websvc.dll). The dropper decrypted an external payload file, debug.xml, using Wincrypt with CALG_3DES_112 and a static embedded key. Persistence was established by creating a service such as WebUpdate and configuring svchost.exe to load a malicious ServiceDll via registry keys under HKLM\System\ControlSet\Services\WebUpdate\Parameters. The final Samurai payload was stored as a compressed, encrypted, base64-encoded blob in registry keys under HKLM\SOFTWARE\Classes\Interface{6FD0637B-85C6-D3A9-CCE9-65A3F73ADED9}, with some variants using {AFDB6869-CAFA-25D2-C0E0-09B80690F21D}.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"From February 26 until early March, we observed a quick escalation and the attacker abusing the ProxyLogon vulnerability to compromise multiple organizations across Europe and Asia."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The first wave of attacks exclusively targeted Microsoft Exchange Servers, which were compromised with Samurai, a sophisticated passive backdoor that usually works on ports 80 and 443. The malware allows arbitrary C# code execution..."
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by ToddyCat; referenced for its persistence technique that hides malware in svchost.exe address space via service/registry manipulation.
A modular .NET (C#) passive backdoor deployed on compromised Microsoft Exchange servers. It uses .NET HTTPListener/HTTP.sys to handle specially crafted HTTP POST requests and supports attacker-supplied encrypted C# source code that is compiled and executed at runtime. It supports modules for remote command execution, file enumeration/exfiltration, and proxying/pivoting for lateral movement, and is persisted via svchost service DLL loading and registry-stored encrypted payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.