Over 4,000 abandoned but still active backdoors were seized and their communication infrastructure was destroyed, as researchers claimed expired domains that were used for their operation.
See also: Cloud Atlas hackers use Microsoft Office vulnerability to distribute backdoors

Backdoors are covert methods of bypassing normal authentication or security checks on a system. Often exploited by malicious actors, they can be created intentionally for maintenance purposes or introduced without the knowledge of the system owner through flaws. Backdoors pose significant risks, as they provide unauthorized access, compromising the integrity and confidentiality of data.
Some of the live malicious programs were developed on web servers of high‑profile targets, including government and university systems, ready to execute commands from any communication domain control tool.
Together with The Shadowserver Foundation, researchers at WatchTowr Labs prevented these domains and their respective victims from falling into the hands of malicious actors. WatchTowr researchers began searching for domains in various web shells and purchased any that had expired, effectively taking control of the backdoors.
See also: Chinese hackers Winnti target other hackers with Glutton backdoor
After creating a logging system, the abandoned but still active malware began sending requests that allowed researchers to identify at least some of the victims.

Since registering more than 40 domains, researchers received communication from more than 4,000 compromised systems trying to "phone home."
Researchers found several types of backdoors, including the “classic” r57shell, the more advanced c99shell , which offers file management and brute-forcing capabilities, and the “ China Chopper ” web shell often associated with APT groups.
The report even mentions a backdoor that exhibited behavior associated with the Lazarus Group, although it later clarifies that it was likely a reuse of the threat actor's domain by others.
Among the diverse set of compromised machines, WatchTowr found multiple systems in China's government infrastructure, including courts, a compromised Nigerian government judicial system, and systems in the Bangladeshi government network
See also: DCOM attack exploits Windows Installer for backdoor access
Additionally, infected systems were found in educational institutions in Thailand, China, and South Korea.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
