DOORME is a native Windows Internet Information Services (IIS) backdoor implemented as a malicious IIS module. It registers an IIS request handler that inspects inbound HTTP traffic before normal IIS processing, allowing operators to authenticate specially crafted requests and covertly interact with compromised internet-facing web servers. The backdoor can return host identity information, generate a host identifier, receive encrypted command data, load shellcode in memory, execute it within the IIS worker process, and exchange input and output with shellcode through named pipes. DOORME employs XOR-obfuscated strings, runtime API resolution, anti-disassembly measures, and control-flow obfuscation to impede analysis. It has been associated with the REF2924 espionage intrusion set, including compromises affecting a foreign affairs organization in an ASEAN member state and telecommunications organizations in Afghanistan. REF2924 has been assessed with moderate confidence to overlap with activity publicly tracked as Winnti and ChamelGang.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DOORME is a native backdoor module that is loaded into a victim's IIS infrastructure and used to provide remote access to the target infrastructure.
DOORME is a native backdoor module that is loaded into a victim's IIS infrastructure and used to provide remote access to the target infrastructure.
The deployment method for malicious IIS modules like DOORME can be found in a referenced blog post.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
DOORME XOR-encrypts strings to evade detection... The malware also employs... Control Flow Obfuscation (CFO) to complicate the analysis of its behavior.
DOORME first resolves the address of LoadLibraryA and GetProcAddress Windows API by parsing the kernel32.dll module export table.
The IIS backdoor monitored incoming HTTP requests and accepted commands through POST requests; SiestaGraph used Microsoft Graph API C2.
U - Download from OneDrive... the file is downloaded from OneDrive by the implant, but uploaded by the attacker.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another malware example observed using control-flow flattening obfuscation.
Mentioned only as another malware example in which control-flow flattening was observed.
A named implant/tool previously observed in the REF2924 intrusion set.
Previously observed malware in the same government victim environment; no functionality is described here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.