Threats Tagged 'backdoor'
View all threats tagged with 'backdoor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'backdoor'
Click on any threat for detailed analysis and mitigation recommendations
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released. Join the discussion | CVE Database V5 | 09/07/2026, 17:15:59 UTC Added: 09/09/2025, 13:33:51 UTC |
Toy Ghouls, a financially motivated group targeting Russian organizations since 2025, has deployed custom backdoors for the first time. Two versions were identified: mqtt-bird-agent using HiveMQ MQTT broker and matrix-bird-agent using Element messenger as command and control infrastructure. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They establish persistence as Windows services, encrypt configuration files using ChaCha20-Poly1305 algorithm, and execute commands via PowerShell or command line. The backdoors collect system metrics including CPU load, memory, and disk usage, and communicate with attackers through unconventional channels. This represents a significant evolution from their previous reliance on public GitHub tools and leaked ransomware builders to custom-developed malware. Join the discussion | AlienVault OTX General | 09/04/2026, 12:34:10 UTC Added: 09/07/2026, 10:22:27 UTC |
ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated. Join the discussion | AlienVault OTX General | 08/31/2026, 11:11:49 UTC Added: 08/31/2026, 15:38:07 UTC |
Three implants named SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS have been found embedded in ZBT router firmware distributed globally, including in the US, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor on port 9992 providing root shell access with trivial MAC address bypass. SPEAKINGSTONE is a phone-home implant capable of DNS hijacking, ISP credential theft, and remote command execution. These implants use plaintext protocols without authentication, making them vulnerable to hijacking by network adversaries. The compromised hardware is found in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commercial devices. A sinkholed backup domain revealed 392 devices, mostly in China, and internet scans found 203 DARKLANTERN instances in 22 countries. Join the discussion | AlienVault OTX General | 08/27/2026, 22:16:24 UTC Added: 08/28/2026, 09:07:13 UTC |
The Iranian-linked cyber-espionage group Tortoiseshell has expanded its malware toolkit with a new reverse SSH tunneling utility disguised as wtsapi32.dll and a C++ backdoor similar to TWOSTROKE malware. The SSH tunnel uses the Windows OpenSSH client to connect to command-and-control servers. The backdoor supports executing files, shell commands, in-memory DLL execution, and file manipulation. Infrastructure analysis shows domains linked to multiple countries including the UAE, Saudi Arabia, UK, Belgium, Canada, Australia, Japan, and the United States, indicating broader targeting beyond the Middle East and US defense and military sectors. The group has been active since 2018 and maintains persistent infrastructure despite domain suspensions. No known exploits in the wild or patches are reported. Join the discussion | AlienVault OTX General | 08/26/2026, 17:18:24 UTC Added: 08/26/2026, 18:37:18 UTC |
The Head Mare APT group exploited two vulnerabilities in TrueConf video conferencing servers to deliver PhantomCore malware to conference participants. Attackers used these vulnerabilities to execute arbitrary code, replace legitimate client installers with malicious versions, and deploy web shells. When participants downloaded the TrueConf client from compromised servers, they received infected installers that deployed PhantomCore backdoor, granting attackers full control over infected systems. On Linux servers, additional backdoors were installed using GitHub as a command and control channel. The vulnerabilities affected TrueConf server versions released since 2022 and were patched in versions 5.3.9, 5.4.9, and 5.5.5 released in June 2026. Organizations whose employees participated in video conferences using TrueConf may have been affected, even if they don't operate their own TrueConf servers. Join the discussion | AlienVault OTX General | 08/21/2026, 07:35:07 UTC Added: 08/21/2026, 08:08:25 UTC |
On August 20, 2026, malicious versions of three Rust crates ([email protected], [email protected], and [email protected]) were published to crates.io. These crates included a typosquatted dependency named proc-macro1, whose build script downloads and executes a remote binary during compilation. This binary installs a backdoor that communicates with command and control servers over HTTPS, exfiltrates host and browser data, enumerates installed applications, and persists via common OS mechanisms such as Registry Run keys, LaunchAgents, or systemd user services. The attack infrastructure overlaps with North Korean threat actor operations, notably the Mastra campaign and previous DPRK-linked supply chain attacks. No official remediation guidance is currently available. Join the discussion | AlienVault OTX General | 08/20/2026, 21:47:21 UTC Added: 08/21/2026, 17:52:14 UTC |
A supply chain attack targeted three popular Rust crates (arrayref, internment, and append-only-vec) by injecting a malicious typosquatted dependency named proc-macro1. This malicious package executed malware during Cargo builds across Linux, macOS, and Windows platforms, delivering backdoors that profiled victims, stole browser data, maintained persistence, and enabled remote command execution. The attack threatened developer workstations, CI/CD pipelines, and release infrastructure. The Rust Security Response Team removed the malicious releases and locked the maintainer's account to mitigate the threat. Join the discussion | AlienVault OTX General | 08/20/2026, 21:47:20 UTC Added: 08/21/2026, 08:22:35 UTC |
A sophisticated backdoor disguised as a legitimate Malwarebytes installer was distributed to over 100,000 machines through compromised automatic updates of one torrent client (Download Studio) and three adblockers (NetShield Kit, My AdBlock, and Net AdBlock). The backdoor creates a fake Malwarebytes installation directory containing legitimate signed files alongside malicious DLL files. Once executed, it establishes persistence through a Windows service and communicates with command-and-control servers to receive configuration updates and additional payloads. The primary observed payloads were cryptocurrency miners, though the infrastructure supports delivery of multiple persistent threats. The attack demonstrates abuse of software update mechanisms and affects primarily users in Russia, Ukraine, and Kazakhstan. Join the discussion | AlienVault OTX General | 08/19/2026, 20:15:03 UTC Added: 08/20/2026, 23:07:12 UTC |
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment. Join the discussion | AlienVault OTX General | 08/17/2026, 15:03:54 UTC Added: 08/18/2026, 09:26:43 UTC |
Showing 1 to 10 of 136 results