Nightdoor

S1147

Malware.View on attack.mitre.org

About this malware

Nightdoor is a backdoor exclusively associated with Daggerfly operations. Nightdoor uses common libraries with MgBot and MacMa, linking these malware families together.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

Nightdoor gathers information on victim system network configuration such as MAC addresses.

T1033
System Owner/User Discovery

Nightdoor gathers information on victim system users and usernames.

T1053.005
Scheduled Task

Nightdoor uses scheduled tasks for persistence to load the final malware payload into memory.

T1057
Process Discovery

Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes.

T1059.003
Windows Command Shell

Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes.

T1070.004
File Deletion

Nightdoor can self-delete.

T1071
Application Layer Protocol

Nightdoor uses TCP and UDP communication for command and control traffic.

T1082
System Information Discovery

Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers.

T1102
Web Service

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1124
System Time Discovery

Nightdoor can identify the system local time information.

T1140
Deobfuscate/Decode Files or Information

Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`.

T1497.001
System Checks

Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments.

T1574
Hijack Execution Flow

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

T1680
Local Storage Discovery

Nightdoor can collect information about disk drives, their total and free space, and file system type.

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET EvasivePanda 2024 Open source
    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.
  2. Symantec Daggerfly 2024 Open source
    Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.