RGDoor

S0258

Malware.View on attack.mitre.org

About this malware

RGDoor is a malicious Internet Information Services (IIS) backdoor developed in the C++ language. RGDoor has been seen deployed on webservers belonging to the Middle East government organizations. RGDoor provides backdoor access to compromised IIS servers.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1033
System Owner/User Discovery

RGDoor executes the whoami on the victim’s machine.

T1059.003
Windows Command Shell

RGDoor uses cmd.exe to execute commands on the victim’s machine.

T1071.001
Web Protocols

RGDoor uses HTTP for C2 communications.

T1105
Ingress Tool Transfer

RGDoor uploads and downloads files to and from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information

RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm.

T1505.004
IIS Components

RGDoor establishes persistence on webservers as an IIS module.

T1560.003
Archive via Custom Method

RGDoor encrypts files with XOR before sending them back to the C2 server.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 RGDoor Jan 2018 Open source
    Falcone, R. (2018, January 25). OilRig uses RGDoor IIS Backdoor on Targets in the Middle East. Retrieved July 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.