HomeSecurityOver 4,000 backdoors seized via expired domains

Over 4,000 backdoors seized via expired domains

Over 4,000 abandoned but still active backdoors were seized and their communication infrastructure was destroyed, as researchers claimed expired domains that were used for their operation.

See also: Cloud Atlas hackers use Microsoft Office vulnerability to distribute backdoors

backdoor domain

Backdoors are covert methods of bypassing normal authentication or security checks on a system. Often exploited by malicious actors, they can be created intentionally for maintenance purposes or introduced without the knowledge of the system owner through flaws. Backdoors pose significant risks, as they provide unauthorized access, compromising the integrity and confidentiality of data.

Some of the live malicious programs were developed on web servers of high‑profile targets, including government and university systems, ready to execute commands from any communication domain control tool.

Together with The Shadowserver Foundation, researchers at WatchTowr Labs prevented these domains and their respective victims from falling into the hands of malicious actors. WatchTowr researchers began searching for domains in various web shells and purchased any that had expired, effectively taking control of the backdoors.

See also: Chinese hackers Winnti target other hackers with Glutton backdoor

After creating a logging system, the abandoned but still active malware began sending requests that allowed researchers to identify at least some of the victims.

Over 4,000 backdoors seized via expired domains

Since registering more than 40 domains, researchers received communication from more than 4,000 compromised systems trying to "phone home."

Researchers found several types of backdoors, including the “classic” r57shell, the more advanced c99shell , which offers file management and brute-forcing capabilities, and the “ China Chopper ” web shell often associated with APT groups.

The report even mentions a backdoor that exhibited behavior associated with the Lazarus Group, although it later clarifies that it was likely a reuse of the threat actor's domain by others.

Among the diverse set of compromised machines, WatchTowr found multiple systems in China's government infrastructure, including courts, a compromised Nigerian government judicial system, and systems in the Bangladeshi government network

See also: DCOM attack exploits Windows Installer for backdoor access

Additionally, infected systems were found in educational institutions in Thailand, China, and South Korea.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS