A new, sophisticated malware family called YiBackdoor has emerged in the cybersecurity sector, posing a significant threat to organizations worldwide.
See also: Russian Gamaredon and Turla install Kazuar Backdoor in Ukraine

This malware, first observed in June 2025, represents a worrying development in backdoor technology, possessing advanced capabilities that allow malicious users to execute arbitrary commands, capture screenshots, collect sensitive system information, and deploy additional malicious plugins on compromised computers.
The malware's architecture exhibits significant code overlap with established threats such as IcedID and Latrodectus, suggesting possible collaboration between groups of malicious users or shared development resources.
Similar to notorious banking trojans like Zloader and Qakbot, IcedID was originally designed to facilitate financial fraud, but has evolved into a primary tool for providing initial access to ransomware operators. YiBackdoor appears to be following this path, potentially acting as a gateway for more destructive cyberattacks.
Zscaler analysts identified YiBackdoor through extensive threat hunting activities and noted its advanced analysis capabilities, designed to evade detection by security researchers and automated sandbox environments.
See also: Mustang Panda develops SnakeDisk USB Worm to distribute Yokai Backdoor

The malware demonstrates advanced virtualization detection techniques, including hypervisor identification for VMware, Xen, KVM, VirtualBox, Microsoft Hyper-V , and Parallels. The malware's limited deployment patterns suggest it may be in development or testing, according to security researchers.
However, its advanced capabilities and its connection to established malware families suggest that broader deployment campaigns could emerge as development progresses. The malicious user's use of local IP addresses in configuration files further supports the assessment that YiBackdoor remains in active development.
YiBackdoor uses a sophisticated process injection technique that sets it apart from conventional malware families. The malware uses a unique approach to achieve code execution inside legitimate system processes, specifically targeting svchost.exe for its injection operations. During the initialization phase, YiBackdoor performs a critical check to determine if it is already running inside a process by examining its memory address against loaded DLL regions. If the malware detects that it has not yet been injected, it creates a new svchost.exe process and begins the injection sequence. The malware allocates memory inside the targeted process and copies its malicious code into the newly created memory region.
See also: 'ChillyHell' backdoor was hidden in certified Mac apps

The most notable aspect of YiBackdoor's injection technique involves patching the Windows API function RtlExitUserProcess with custom assembly code. This patch redirects execution flow to the YiBackdoor entry point when the function is called, effectively hijacking the shutdown process. Persistence is established through manipulation of the Windows Registry, where YiBackdoor copies itself to a randomly named directory and creates registry entries using regsvr32.exe to automatically run at system startup.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
