Skip to content

MLTBackdoor

MLTBackdoor is a newly identified backdoor malware family reported by Zscaler ThreatLabz in May 2026 and assessed as likely being used by a ransomware-related threat actor.

MLTBackdoor

Family profile

MLTBackdoor is a newly identified backdoor malware family reported by Zscaler ThreatLabz in May 2026 and assessed as likely being used by a ransomware-related threat actor. It has been observed delivered through a multi-stage ClickFix infection chain that uses fake error messages or fraudulent browser-update style lures to trick victims into copying, pasting, and executing malicious PowerShell or command-line content. In the documented chain, an automotive-themed lure leads to download of an archive from a DGA-generated domain; the archive contains endpointdlp.dll and an RC4-encrypted data.bin payload, and the malware is installed via DLL sideloading using the legitimate Microsoft Defender binary mpextms.exe. After installation, it can self-update and reuse the endpointdlp.dll filename for disguise.

MLTBackdoor is heavily obfuscated and anti-analysis aware. Reported techniques include mixed boolean-arithmetic obfuscation, control-flow flattening, stack-built strings, API hashing, and Hell’s Gate-style indirect system calls; one analysis assessed roughly 95% of the code as unnecessary mathematical operations intended to hinder reverse engineering. It performs ten environment checks covering virtualization, debuggers, analysis tools, sandbox artifacts, low RAM, single-CPU systems, and low uptime, and sends the resulting bitmask to its command-and-control server.

Functionally, MLTBackdoor provides remote access and post-compromise capability including file upload, file download, directory listing, delete, rename, and folder creation. It also includes a Beacon Object File loader that executes BOFs in memory, enabling fileless extension of functionality for post-exploitation activity such as reconnaissance, privilege escalation, and lateral movement. The BOF support includes standard Beacon-style imports and additional BeaconNt* wrappers backed by the malware’s own indirect system call layer.

For command and control, MLTBackdoor uses a custom encrypted binary protocol over TLS/port 443, with reported use of the fixed path /api/v1/telemetry and the User-Agent Microsoft-Delivery-Optimization/10.1 to blend with legitimate traffic. It derives session keys using ECDH on NIST P-256 and encrypts subsequent communications with AES-256-GCM. The malware supports both hardcoded C2 domains and a date-based domain generation algorithm that can produce a new domain daily for resilience.

High-confidence indicators mentioned in the content include the domains hrs2y15sungu.com, carrolc.com, cwrtwright.com, and thomphon.com; the URL powwowski.com/payloads/update.zip; and the SHA-256 hashes 1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984, 46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93, 9e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66, ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ec, 1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cf, 2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494, and d34e4038c5c80728f9648ba84833f69bc1ccea82e2e8e748b7b7f02fb687b92b.

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

MLTBackdoor in ATT&CK

29 distinct techniques