Also known as: Custom HDoor
Executive Summary
HDoor is a Windows backdoor used by the Naikon group to maintain persistence, exfiltrate data, and facilitate lateral movement within corporate environments. The malware establishes encrypted C&C channels, employs registry or scheduled task persistence, and can harvest credentials from local stores. It poses significant risk for long‑term espionage, especially against organizations with complex Windows infrastructures.
Enhanced Description
HDoor, sometimes referred to as Custom HDoor, is a Windows-based backdoor that has been tailored and employed by the Naikon threat group since at least 2015. The malware was first identified in a report by Baumgartner on Naikon, illustrating its use as part of the group's persistent espionage toolkit. In operation, HDoor establishes a covert command‑and‑control channel with the adversary’s servers, often over encrypted HTTP or HTTPS traffic to blend with legitimate web traffic. Once executed it typically creates persistence mechanisms such as registry Run keys and scheduled tasks, enabling automatic reloading upon system boot or user logon. Beyond remote execution, the worm can exfiltrate files, capture screenshots, and harvest credentials from local credential stores. It also supports lateral movement through standard Windows credentials, leveraging native system tools like WMI and PowerShell to spawn new sessions on compromised hosts. The code is obfuscated, making static analysis difficult, while runtime behavior includes attempts to detect sandbox or debugging environments. The impact of HDoor lies largely in its support for a broad range of espionage activities—remote control, data theft, and persistence—thereby providing adversaries with persistent footholds that can be leveraged for long-term reconnaissance and lateral infiltration across enterprise networks.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information about HDoor is limited primarily to attribution and a high‑level description; no specific indicators such as file hashes, IP addresses or DNS entries were supplied. Consequently confidence in detailed behavior and detection tactics is moderate. Further analysis of actual samples and network logs would be required to confirm the threat scenario and refine defensive measures.
HDoor is malware that has been customized and used by the Naikon group. (Citation: Baumgartner Naikon 2015)