Skip to content

Malware

TernDoor

According to Cisco Talos, TernDoor is a Windows backdoor implant delivered as shellcode via a side-loaded DLL-based loader, with the blog not specifying its implementation language.

TernDoor is a Windows malware family operated by UAT-9244.

Background

Cisco Talos describes TernDoor as a Windows backdoor delivered as shellcode through a side-loaded, DLL-based loader; the blog does not state which language it is written in. The implant persists via scheduled tasks or registry run keys, pulls an embedded configuration to reach its command-and-control, and offers features including remote command execution, file manipulation, gathering system information, and removing itself. It additionally drops an encrypted kernel-mode driver capable of concealing malicious components and of generically suspending, resuming, or killing selected processes, aiding both evasion and process control. Before executing, TernDoor confirms it has been injected into a legitimate system process, helping it blend in with normal activity.


Source: Malpedia (Fraunhofer FKIE).