HomeSecuritySquidoor malware attacks global organizations

Squidoor malware attacks global organizations

A sophisticated backdoor malware called “Squidoor” is being developed by suspected Chinese malicious actors and is targeting organizations across South America and Southeast Asia.

See also: Phishing: Fake CAPTCHAs deliver Lumma malware

Squidoor malware

Malware, which is designed for complete stealth, provides attackers with a variety of capabilities to maintain continuous access to compromised networks, while avoiding detection by sophisticated security systems.

Initial access is primarily achieved through the exploitation of vulnerabilities in Internet Information Services (IIS) servers, followed by the installation of multiple websites that act as permanent backdoors. These web shells exhibit significant similarities in their structure and obfuscation techniques, suggesting a common origin.

Palo Alto Networks researchers have identified the Squidoor malware as a sophisticated cross-platform backdoor specifically built to operate undetected in highly monitored and secure networks.

See also: GrassCall: Fake job interviews distribute malware

The malware appears in versions for both Windows and Linux, confirming the threat actor's commitment to impact diverse environments, regardless of operating system.

Squidoor malware attacks global organizations

The technical complexity of the Squidoor malware is clearly evident in its communication mechanisms.

The Windows version provides support for ten different command and control (C2) communication protocols , while the Linux version supports nine

These techniques include communication over HTTP , TCP/UDP reverse connections , DNS tunneling , as well as communication over Microsoft Outlook APIs, allowing attackers to adapt to a variety of networks and security measures.

The attackers then leveraged curl and Impacket to spread the web shells to various servers within the compromised networks.

See also: LightSpy malware: New version steals data from social media

Backdoor malware, such as Squidoor, is a type of malware designed to provide unauthorized access to a computer, network, or system by bypassing standard authentication and security measures. It typically allows an attacker to remotely control a system without the user's knowledge or consent. The backdoor acts as a hidden entry point for hackers to exploit the system later, even if other security features, such as firewalls or antivirus programs, are in place.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS