Back Orifice (often shortened to BO) is a well-known early Remote Access Trojan/remote administration tool for Microsoft Windows that enables remote control of an infected system. The provided content describes it as a client-server tool in which a server component runs on the victim machine and a GUI client is used by the operator to issue commands and receive responses. It is associated with the Cult of the Dead Cow (cDc) hacker group and is described as having been publicly released in 1998, including a debut at DEF CON 6; the related Back Orifice 2000 (BO2k) version is described as released in 1999. The malware is repeatedly identified as a long-established RAT from the mid-to-late 1990s and as an influential predecessor to later families such as Sub7, whose author described an early release as a clone of Back Orifice.
The content states that Back Orifice targets Microsoft Windows systems and allows an attacker to control a computer remotely. In the BO2k analysis, the payload is configured before deployment, including embedding parameters such as the listening port; one analyzed sample was configured to bind to TCP port 60000. Historical references in the content also associate Back Orifice with UDP port 31337. Reverse engineering described in the source links internal functionality to features including Ping and keylogging. More generally, the surrounding RAT context in the content attributes RAT capabilities such as covert surveillance, unauthorized remote access, browsing and copying files, changing settings, monitoring user behavior, using the victim’s Internet connection, and collecting data such as keystrokes, usernames, passwords, screenshots, browser history, emails, and chat logs.
The content notes that Back Orifice communications could be protected with XOR encoding and optional 3DES encryption, with one analysis recovering an XOR key of 2b 34 6c 46 from observed traffic using a known-plaintext approach. It characterizes Back Orifice as an early-generation RAT that relied on direct connections and static payload configuration rather than the reverse-connection models common in later malware.
Infection and delivery details in the provided material are historical and contextual rather than tied to a single campaign. The content states RATs such as Back Orifice may be installed through malicious email attachments, malicious links, download packages, torrent files, social engineering, or temporary physical access. It also specifically notes that a 2000 Microsoft Outlook/Outlook Express Date-field buffer overflow could be used to install backdoor malware such as Back Orifice on victim systems without requiring a malicious attachment to be opened.
The content does not identify a specific modern threat actor using Back Orifice operationally, but it does strongly associate the malware’s creation and release with Cult of the Dead Cow. No industry-specific targeting is provided; the references are broad and historical, including use for unauthorized access, corporate espionage, and pranks. High-confidence indicators directly mentioned in the content include the name/alias Back Orifice, abbreviation BO, UDP port 31337, and in one BO2k lab configuration TCP port 60000.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The hacker group was particularly famous for its easy-to-use Back Orifice spyware trojan released in 1998, which was as good for corporate espionage as it was for humorous office pranks.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
A newly discovered vulnerability in Microsoft's Outlook and Outlook Express programs leave thousands of computers open to attack from malicious email... The vulnerability doesn't require any attachment to the email; Outlook users need only read a message to be hit. Outlook Express users are even more vulnerable, and can fall prey to malicious code without reading the message, or even being at their computer when it comes in.
The bug is a classic "buffer overflow" error in the section of Outlook that parses the Date field of each incoming email. By padding the date with a long string of characters, an attacker can escape from the area of memory reserved for storing it, and into a section that executes instructions.
Back Orifice officially provides XOR encoding and 3DES encryption for protecting the communication.
The “Server command client” allows the controller sends C2 commands to the payload. The mechanism works as follows: The controller sends C2 commands to the payload, the payload executes the corresponding funcitonallity and then return it.
Remote Access Trojans are programs that provide the capability to allow covert surveillance or the ability to gain unauthorized access to a victim PC... they provide the capability for an attacker to gain unauthorized remote access to the victim machine via specially configured communication protocols which are set up upon initial infection of the victim computer.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early-generation remote access trojan from the 1990s. The article notes these RATs generally transferred data in plain text, with Back Orifice as an exception because its protection could be cracked.
A remote access tool with client-server architecture that enables remote control of Windows systems. The article discusses versions 1.20 and 2000, including payload configuration, command-and-control functionality, XOR-encoded communications, optional 3DES protection, and features such as keylogging.
A long-established remote access trojan used to provide covert unauthorized remote access to victim systems.
A spyware trojan released by Cult of the Dead Cow in 1998, described as easy to use and suitable for corporate espionage or pranks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.