Skip to content

MKDOOR

MKDOOR is a modular Windows backdoor associated with China-aligned intrusion activity and observed in campaigns using the PeckBirdy JScript command-and-control framework.

MKDOOR

Family profile

MKDOOR is a modular Windows backdoor associated with China-aligned intrusion activity and observed in campaigns using the PeckBirdy JScript command-and-control framework. It is designed as a two-component system consisting of a downloader and a backdoor module. In observed operations, victims were lured through fake Google Chrome update pages delivered from compromised websites, after which the downloader retrieved and launched the backdoor component.

The downloader includes defense-evasion measures intended to reduce detection on infected hosts, including abuse of Microsoft Defender exclusions. MKDOOR also attempted to disguise command-and-control traffic as legitimate Microsoft-related web activity. Reporting further indicates behavioral overlap with BIOPASS RAT in its use of a localhost HTTP listener, suggesting support for local coordination with browser-based or watering-hole components.

MKDOOR was used in the SHADOW-VOID-044 campaign, which targeted the Chinese gambling sector through watering-hole compromises, and has been linked in that context to infrastructure and activity overlaps associated with UNC3569. The malware forms part of a broader modular toolset delivered alongside other backdoors such as HOLODONUT to support stealthy post-compromise access and cyber-espionage objectives. High-confidence reporting supports MKDOOR as a backdoor rather than merely a downloader, although its architecture includes a dedicated downloader stage.

Capabilities

  • Defense Evasion
  • Post Exploitation

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

1 named in public reporting
Earth Lusca

After downloading and analyzing the file, we identified another modularly-designed backdoor, MKDOOR, which is composed of two different modules: the downloader and the backdoor.

Exploited software

Vulnerabilities linked to MKDOOR

1 CVEs

MITRE ATT&CK

MKDOOR in ATT&CK

8 distinct techniques

Reporting

Research mentioning MKDOOR

Aug 19
Trendai Security

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | TrendAI (US)

Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.