Skip to content

Taidoor

Taidoor is a Windows backdoor associated with long-running targeted intrusion activity, particularly espionage-oriented campaigns affecting organizations in the Asia-Pacific region.

Taidoor

Family profile

Taidoor is a Windows backdoor associated with long-running targeted intrusion activity, particularly espionage-oriented campaigns affecting organizations in the Asia-Pacific region. It has been active since at least 2009 and has been linked to spearphishing operations in which victims are induced to open malicious document attachments. Observed delivery methods include seemingly benign documents and malicious Microsoft Office files exploiting vulnerabilities such as CVE-2012-0158, as well as earlier exploit-document chains associated with Office RTF exploitation.

Once executed, Taidoor provides remote access and host control capabilities typical of an espionage backdoor. Documented functionality includes process discovery, collection of local system time, and collection of network adapter information including MAC address data. It can query and modify the Windows Registry, including use of autorun locations for persistence, and has been observed establishing persistence through a current-user Run key. It also supports file deletion and file upload from compromised hosts, enabling both cleanup and data theft operations.

Taidoor uses native Windows APIs extensively for execution and runtime behavior, including dynamic loading of libraries and API resolution. It can perform DLL loading and has been observed using encrypted or obfuscated strings internally. For command-and-control communications, Taidoor has used HTTP with RC4-encrypted message bodies. The malware has been classified by vendors as a trojan or backdoor, but the directly supported behavior most strongly characterizes it as a backdoor used in targeted attacks against Windows systems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Reconnaissance

Samples

Recent samples

3 sandbox samples in the Derp library, newest 3 shown

Exploited software

Vulnerabilities linked to Taidoor

3 CVEs

MITRE ATT&CK

Taidoor in ATT&CK

28 distinct techniques

Reporting

Research mentioning Taidoor

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.