After downloading and analyzing the file, we identified another modularly-designed backdoor, MKDOOR, which is composed of two different modules: the downloader and the backdoor.
MKDOOR
MKDOOR is a modular Windows backdoor associated with China-aligned intrusion activity and observed in campaigns using the PeckBirdy JScript command-and-control framework.
MKDOOR
Family profile
MKDOOR is a modular Windows backdoor associated with China-aligned intrusion activity and observed in campaigns using the PeckBirdy JScript command-and-control framework. It is designed as a two-component system consisting of a downloader and a backdoor module. In observed operations, victims were lured through fake Google Chrome update pages delivered from compromised websites, after which the downloader retrieved and launched the backdoor component.
The downloader includes defense-evasion measures intended to reduce detection on infected hosts, including abuse of Microsoft Defender exclusions. MKDOOR also attempted to disguise command-and-control traffic as legitimate Microsoft-related web activity. Reporting further indicates behavioral overlap with BIOPASS RAT in its use of a localhost HTTP listener, suggesting support for local coordination with browser-based or watering-hole components.
MKDOOR was used in the SHADOW-VOID-044 campaign, which targeted the Chinese gambling sector through watering-hole compromises, and has been linked in that context to infrastructure and activity overlaps associated with UNC3569. The malware forms part of a broader modular toolset delivered alongside other backdoors such as HOLODONUT to support stealthy post-compromise access and cyber-espionage objectives. High-confidence reporting supports MKDOOR as a backdoor rather than merely a downloader, although its architecture includes a dedicated downloader stage.
Capabilities
- Defense Evasion
- Post Exploitation
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to MKDOOR
1 CVEsMITRE ATT&CK
MKDOOR in ATT&CK
8 distinct techniquesReporting