Researchers disclosed SockDetour, a previously undocumented Windows backdoor used against U.S. defense contractors as a stealthy secondary implant for persistence. The malware operates filelessly and socketlessly, hijacking legitimate processes' network sockets with the Microsoft Detours library to create an encrypted command-and-control channel that is difficult to spot through host or network monitoring. Palo Alto Networks Unit 42 said at least four U.S.-based defense contractors were targeted and confirmed compromise at one organization, with compilation artifacts indicating the tool may have been in use since at least July 2019.
Unit 42 linked the activity to the China-linked TiltedTemple cluster, also tracked by Microsoft as DEV-0322, and said the campaign overlapped with late-2021 intrusions involving Zoho ManageEngine exploitation; reporting also noted possible ties to APT27 based on tactics and targeting. In one case, attackers delivered SockDetour from an external FTP server hosted on a compromised QNAP NAS device that had likely been exploited through CVE-2021-28799, the same flaw previously abused to deploy eCh0raix and associated with earlier QLocker ransomware activity, showing how vulnerable internet-facing NAS infrastructure was repurposed to support espionage operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported that TiltedTemple conducted a 2021 campaign exploiting ServiceDesk Plus beginning on October 25, 2021, following earlier Zoho-related campaigns.
After first observing SockDetour on July 27, 2021, Unit 42 identified three additional defense organizations targeted with the same backdoor, bringing the total to at least four targeted contractors with one confirmed compromise.
On July 27, 2021, attackers delivered SockDetour from an external FTP server hosted on a compromised QNAP NAS device to a U.S.-based defense contractor's internet-facing Windows server. Researchers assessed the NAS may have been compromised via CVE-2021-28799 and noted it had previously been infected with QLocker ransomware.
Unit 42 observed an attack exploiting CVE-2021-28799 against QNAP HBS 3 on June 21, marking the first instance they knew of where the flaw was used to deliver eCh0raix ransomware.
Victim reports cited by Unit 42 indicated that eCh0raix operators successfully extorted ransom payments as recently as June 16, 2021.
QNAP disclosed CVE-2021-28799, an improper authorization flaw affecting Hybrid Backup Sync 3 that could allow remote attackers to log in to affected devices.
Unit 42 reported that the first sample of a combined eCh0raix ransomware variant capable of targeting both QNAP and Synology NAS devices dates to September 2020.
Unit 42 assessed from compilation timestamp evidence that the previously undocumented SockDetour backdoor may have been in use since at least July 2019, suggesting it evaded detection for more than two and a half years.
Unit 42 disclosed the previously undocumented SockDetour backdoor, describing it as a fileless, socketless implant used against U.S. defense contractors and linking the activity to the China-linked TiltedTemple cluster through overlapping infrastructure.
Unit 42 published research describing a new eCh0raix ransomware variant that targets both QNAP and Synology NAS devices and documented in-the-wild exploitation of CVE-2021-28799.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.