BlindDoor is a simple backdoor used in a 2026 intrusion cluster attributed to a likely initial access broker supporting ransomware operations. It was deployed as a secondary tool after social-engineering-based compromise of Windows enterprise endpoints, where attackers used spam bombing, Microsoft Teams impersonation of IT or helpdesk staff, and Quick Assist remote sessions to obtain access before staging additional malware with PowerShell.
BlindDoor operates over a basic socket-based command-and-control protocol. After launch, it notifies its controller with a READY message, receives newline-delimited commands, executes them on the compromised host, and responds with OK after each command. Observed behavior indicates it provides remote command execution but does not return command output through this protocol, distinguishing it from more feature-rich backdoors used in the same operations.
The malware appeared alongside other tooling including GoGRPC, RevSocket, PyGRPC, S3Siphon, and RSOX, reflecting a broader toolkit for persistence, remote access, tunneling, reconnaissance, and data theft in corporate environments. BlindDoor is best characterized as a lightweight backdoor used for post-compromise access on Windows systems during intrusions that may precede extortion or ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Simple backdoor using a READY/OK socket protocol, deployed as an additional tool during post-compromise activity.
A tool used in the same operation, providing remote access capability as part of the broader intrusion set.
Additional malware used in the same campaigns alongside GoGRPC.
A backdoor that notifies its C2 with a READY message, receives newline-separated commands, executes them on the victim system, replies with OK after each command, and attempts to maintain or reestablish the socket connection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.