{"id":2525,"date":"2025-03-12T10:08:03","date_gmt":"2025-03-12T10:08:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/12\/chinese-hackers-new-malware-dubbed-squidoor-attacking-global-organizations\/"},"modified":"2025-03-12T10:08:03","modified_gmt":"2025-03-12T10:08:03","slug":"chinese-hackers-new-malware-dubbed-squidoor-attacking-global-organizations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/12\/chinese-hackers-new-malware-dubbed-squidoor-attacking-global-organizations\/","title":{"rendered":"Chinese Hackers New Malware Dubbed \u2018Squidoor\u2019 Attacking Global Organizations"},"content":{"rendered":"<p>    Chinese Hackers New Malware Dubbed \u2018Squidoor\u2019 Attacking Global Organizations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated backdoor malware called \u201cSquidoor\u201d being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia.<\/p>\n<p>The malware, designed for exceptional stealth, offers attackers multiple methods to maintain persistent access to compromised networks while evading detection from <a href=\"https:\/\/cybersecuritynews.com\/endpoint-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">advanced security<\/a> systems.<\/p>\n<p>Initial access is gained primarily through exploiting vulnerabilities in Internet Information Services (IIS) servers, followed by the deployment of multiple web shells that serve as persistent backdoors.<\/p>\n<p>These web shells exhibit significant similarities in their structure and obfuscation techniques, suggesting a common origin.<\/p>\n<p>Palo Alto Networks researchers <a href=\"https:\/\/unit42.paloaltonetworks.com\/advanced-backdoor-squidoor\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that Squidoor is a sophisticated multi-platform backdoor built specifically to operate undetected in highly monitored and secured networks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhkLelbw8gOfUwnXJ3HoUvuOqdjVpW_x23m1F9Z_JZTwOWlw8tERxHffErx0vqJoP1Ea3wYyphIsgKFu3D1uzE6qP48x54VNQd7QMMlBJXZ29tD48a-Gxgy1e0G3ZR5hf1DzqxdYdx1_9rKS-tAk1izOBCXtzKHFj5gHJPUF03KcLGKAQUPCqqUAaXYdOs\/s16000\/Execution%2520flow%2520%28Source%2520-%2520Plao%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Execution flow (Source \u2013 Plao Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>The malware exists in both Windows and Linux variants, demonstrating the threat actor\u2019s commitment to compromising diverse environments regardless of operating system.<\/p>\n<p>The technical sophistication of Squidoor is particularly evident in its communication mechanisms.<\/p>\n<p>The Windows version supports ten different protocols for command and control (C2) communication, while the Linux version supports nine.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh4illyHuR1VCMmOp7HOTHOtkJbbMLFyleqyyGgucwGyUNK-PKnnUJdODLZBFvOUcNX1Uofsxjv76fOWMuAEuhvrnIcAWujpsT2d-7d5AVZHzWTPp4FP1IDZDmVvO8VnmDtK2XirZjPzTRHIxWqR_tYTi95q2HUCVwDXV35UNCzhFeRo90s9GYH1Ne4h-c\/s16000\/Flow%2520of%2520the%2520communication%2520mechanism%2520via%2520Outlook%2520API%2520%28Source%2520-%2520Plao%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Flow of the communication mechanism via Outlook API (Source \u2013 Plao Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>These methods include HTTP-based communication, reverse TCP\/UDP connections, DNS tunneling, and even Microsoft Outlook mail API communication, allowing attackers to adapt to different network environments and security controls.<\/p>\n<p>\u201cThe threat actor stored some of the <a href=\"https:\/\/cybersecuritynews.com\/ai-webshell-detection-detailed-overview\/\" target=\"_blank\" rel=\"noreferrer noopener\">web shells<\/a> on bashupload.com and downloaded and decoded them using certutil,\u201d according to the research report.<\/p>\n<p>The attackers then used curl and Impacket to spread the web shells across different servers within compromised networks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Outlook Transport Channel: A Stealthy Communication Vector<\/strong><\/h2>\n<p>Perhaps the most innovative aspect of Squidoor is its ability to leverage Microsoft Outlook as a covert communication channel.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhKYmqI7rwxpXr63zjk0x57RFYfhk8Yg40HRRXfHSJYau4V4ySJUw2xAVW3j2UpYrtee6GrsuZ4POK-12ceotTM2cn_I-Mug-H05lt_moyQcogHit0esREQ41NGozAjC88AVOEaA1_3V1Dh9M4cxeH7bt26RMjaMUQ_6bTEcX09Qk53rB19EKB86nFJWBU\/s16000\/HTTP%2520POST%2520request%2520by%2520Squidoor%2520for%2520logging%2520in%2520to%2520the%2520Microsoft%2520identity%2520platform%2520%28Source%2520-%2520Plao%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">HTTP POST request by Squidoor for logging in to the Microsoft identity platform (Source \u2013 Plao Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>When configured to use this method, the malware logs into the Microsoft identity platform using a hard-coded refresh token.<\/p>\n<p>It then queries the drafts folder in Outlook, searching for emails with specific subject line patterns containing randomly generated numbers that help differentiate between different Squidoor implants.<\/p>\n<p>The communication flow involves sophisticated encoding and <a href=\"https:\/\/cybersecuritynews.com\/end-to-end-encryption\/\" target=\"_blank\" rel=\"noreferrer noopener\">encryption techniques<\/a>.<\/p>\n<p>Email contents undergo multiple stages of processing: transformation using CryptStringToBinaryA WinAPI, Base64 decoding, a combination of AES and custom XOR decryption, and finally zlib decompression.<\/p>\n<p>This deobfuscated content provides commands for Squidoor to execute, ranging from reconnaissance to payload injection.<\/p>\n<p>For persistence, Squidoor creates a scheduled task named \u201cMicrosoftWindowsAppIDEPolicyManager\u201d that executes the malicious shellcode at regular intervals, ensuring the backdoor remains active even after system reboots.<\/p>\n<p>The malware can also inject additional payloads into legitimate processes like mspaint.exe, conhost.exe, and taskhostw.exe to further conceal its activities.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013 Analyse Malware Incidents &amp; get live Access with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=ti_feeds&amp;utm_content=demo&amp;utm_term=110325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-new-malware-dubbed-squidoor\/\">Chinese Hackers New Malware Dubbed \u2018Squidoor\u2019 Attacking Global Organizations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-new-malware-dubbed-squidoor\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese Hackers New Malware Dubbed \u2018Squidoor\u2019 Attacking Global Organizations A sophisticated backdoor malware called \u201cSquidoor\u201d being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia. The malware, designed for exceptional stealth, offers attackers multiple methods to maintain persistent access to compromised networks while evading detection from advanced security systems. Initial [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,258,649],"tags":[130],"class_list":["post-2525","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2525"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2525"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2525\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}