Taidoor

S0011

Malware.View on attack.mitre.org

About this malware

Taidoor is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on victim networks. Taidoor has primarily been used against Taiwanese government organizations since at least 2010.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1005
Data from Local System

Taidoor can upload data and files from a victim's machine.

T1012
Query Registry

Taidoor can query the Registry on compromised hosts using RegQueryValueExA.

T1016
System Network Configuration Discovery

Taidoor has collected the MAC address of a compromised host; it can also use GetAdaptersInfo to identify network adapters.

T1027.013
Encrypted/Encoded File

Taidoor can use encrypted string blocks for obfuscation.

T1055.001
Dynamic-link Library Injection

Taidoor can perform DLL loading.

T1057
Process Discovery

Taidoor can use GetCurrentProcessId for process discovery.

T1059.003
Windows Command Shell

Taidoor can copy cmd.exe into the system temp folder.

T1070.004
File Deletion

Taidoor can use DeleteFileA to remove files from infected hosts.

T1071.001
Web Protocols

Taidoor has used HTTP GET and POST requests for C2.

T1083
File and Directory Discovery

Taidoor can search for specific files.

T1095
Non-Application Layer Protocol

Taidoor can use TCP for C2 communications.

T1105
Ingress Tool Transfer

Taidoor has downloaded additional files onto a compromised host.

T1106
Native API

Taidoor has the ability to use native APIs for execution including GetProcessHeap, GetProcAddress, and LoadLibrary.

T1112
Modify Registry

Taidoor has the ability to modify the Registry on compromised hosts using RegDeleteValueA and RegCreateKeyExA.

T1124
System Time Discovery

Taidoor can use GetLocalTime and GetSystemTime to collect system time.

View all 20 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. CISA MAR-10292089-1.v2 TAIDOOR August 2021 Open source
    CISA, FBI, DOD. (2021, August). MAR-10292089-1.v2 – Chinese Remote Access Trojan: TAIDOOR. Retrieved August 24, 2021.
  2. TrendMicro Taidoor Open source
    Trend Micro. (2012). The Taidoor Campaign. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.