Taidoor
Taidoor is a Windows backdoor associated with long-running targeted intrusion activity, particularly espionage-oriented campaigns affecting organizations in the Asia-Pacific region.
Taidoor
Family profile
Taidoor is a Windows backdoor associated with long-running targeted intrusion activity, particularly espionage-oriented campaigns affecting organizations in the Asia-Pacific region. It has been active since at least 2009 and has been linked to spearphishing operations in which victims are induced to open malicious document attachments. Observed delivery methods include seemingly benign documents and malicious Microsoft Office files exploiting vulnerabilities such as CVE-2012-0158, as well as earlier exploit-document chains associated with Office RTF exploitation.
Once executed, Taidoor provides remote access and host control capabilities typical of an espionage backdoor. Documented functionality includes process discovery, collection of local system time, and collection of network adapter information including MAC address data. It can query and modify the Windows Registry, including use of autorun locations for persistence, and has been observed establishing persistence through a current-user Run key. It also supports file deletion and file upload from compromised hosts, enabling both cleanup and data theft operations.
Taidoor uses native Windows APIs extensively for execution and runtime behavior, including dynamic loading of libraries and API resolution. It can perform DLL loading and has been observed using encrypted or obfuscated strings internally. For command-and-control communications, Taidoor has used HTTP with RC4-encrypted message bodies. The malware has been classified by vendors as a trojan or backdoor, but the directly supported behavior most strongly characterizes it as a backdoor used in targeted attacks against Windows systems.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Reconnaissance
Samples
Recent samples
3 sandbox samples in the Derp library, newest 3 shown
Exploited software
Vulnerabilities linked to Taidoor
3 CVEsMITRE ATT&CK
Taidoor in ATT&CK
28 distinct techniquesReporting