LuciDoor is a C++ backdoor used by the China-aligned threat activity cluster UnsolicitedBooker (active since at least March 2023). It has been observed in campaigns reported by Positive Technologies targeting telecommunications organizations in Kyrgyzstan and Tajikistan (with earlier UnsolicitedBooker targeting including Saudi Arabian entities).
Delivery/infection chain: intrusions typically start with phishing emails carrying malicious Microsoft Office documents that prompt victims to enable content; embedded macros then drop a loader (LuciLoad) which deploys the LuciDoor backdoor. In some related UnsolicitedBooker activity, infrastructure included compromised routers used as command-and-control (C2).
Capabilities/behavior: LuciDoor communicates with a C2 server, collects basic system information, and exfiltrates it to the C2 in encrypted form. It supports arbitrary command execution via cmd.exe, can write files to the system, and can upload files (exfiltration).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UnsolicitedBooker, a China-aligned threat actor active since at least March 2023, has deployed two distinct backdoors, LuciDoor and MarsSnake, in recent cyberattacks.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in targeted intrusions; capable of collecting system information, executing arbitrary commands, and exfiltrating data.
C++ backdoor that communicates with a C2 server, collects basic system information, exfiltrates it in encrypted form, and can execute commands (via cmd.exe) plus read/write/upload files.
Backdoor used in a campaign targeting telecommunications companies in Kyrgyzstan and Tajikistan.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.