RGDoor

Malware updated a month ago (2024-09-12T00:18:01.639Z)
Download STIX
Preview STIX
RGDoor is a type of malware, specifically an Internet Information Services (IIS) backdoor, attributed to APT34. It is designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites. RGDoor checks all inbound POST requests for commands, meaning the actor does not need to use a specific URL to interact with it. The malware operates as a secondary backdoor, deployed by actors to regain access to a compromised webserver if a victim organization detects and removes the primary TwoFace shell. The evolution of IIS backdoors has seen a progression from RGDoor to CacheHTTP, and from IIS Group 2 to RGDoor. This evolution aligns with the communication technique observed in older versions of RGDoor. Moreover, there seems to be a close relationship between APT34 and Greenbug, with overlapping Tactics, Techniques, and Procedures (TTPs), and targets in the Middle East. This suggests that these tools, CacheHttp, IISGroup 2, and RGDoor, could potentially be variants of the same tool. To monitor inbound RGDoor requests, administrators must configure logging of Cookie fields in IIS, which can be selected in the W3C Logging Fields dialog in IIS Manager. By default, IIS does not log the values within Cookie fields of inbound HTTP requests, which would contain commands issued by actors to RGDoor. The RGDoor DLL (HTTPParser.dll) is loaded into IIS using the module name HTTPParser, as depicted in Figure 2. Figure 1 shows the specific command used to install RGDoor on an IIS server.
Description last updated: 2024-09-12T00:17:14.601Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Iis
Backdoor
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the RGDoor Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more