C6DOOR is a simple custom backdoor compiled with Go. It was identified in reporting on China-linked APT Tropic Trooper (also tracked as Pirate Panda, KeyBoy, APT23, Bronze Hobart, and Earth Centaur). Researchers found C6DOOR among malware delivered in Tropic Trooper intrusion activity, alongside GTELAM and other tooling such as DaveShell, Donut loader, Merlin Agent, Apollo Agent, EntryShell, Xiangoop loader variants, and a watermarked Cobalt Strike beacon. The broader activity targeted specific individuals in Japan, Taiwan, and South Korea, with historical Tropic Trooper targeting including government, military, healthcare, transportation, and high-tech organizations. Reported infection tradecraft in the same campaign set included delivery through a compromised software update process enabled by DNS hijacking via a victim’s compromised home router, as well as related lure-based delivery using trojanized software. The provided content does not include C6DOOR-specific indicators of compromise or detailed functionality beyond it being a simple Go-based custom backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We decrypted these and found new malware ... and C6DOOR, a simple [custom] backdoor compiled with Go.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A simple custom backdoor compiled with Go and used in Tropic Trooper activity.
Backdoor delivered via hijacked update server in Taiwan-focused espionage campaign; no further details in excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.