PULSE NAME
Squidoor: Suspected Chinese Threat Actor’s Backdoor Targets Global Organizations
WHITE Squidoor AlienVault 2025-02-27 Modified: 2025-03-29
37
IOCs
MEDIUM VOLUME
Since at least March 2023, a suspected Chinese threat actor has been targeting government, defense, telecommunications, education, and aviation sectors in Southeast Asia and South America. The attackers employ a sophisticated backdoor known as Squidoor, which affects both Windows and Linux systems. Squidoor is modular and designed for stealth, utilizing multiple communication protocols—including Outlook API, DNS tunneling, and ICMP tunneling—to establish covert channels with command and control servers. Initial access is typically achieved by exploiting vulnerabilities in Internet Information Services (IIS) servers, followed by the deployment of obfuscated web shells for persistent access.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (5 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 2fdea656bf50277c8d728e1a005bf1e5157c68d0 SHA1 of 83406905710e52f6af35b4b3c27549a12c28a628c492429d3a411fdb2d28cc8c 2025-02-27
FileHash-SHA1 7e2366cf665c602237e988954700cd48859fb197 SHA1 of 3fcfc4cb94d133563b17efe03f013e645fa2f878576282805ff5e58b907d2381 2025-02-27
FileHash-SHA1 a1376a0760c0c327c2ff370cecdf755dfa53eca5 SHA1 of f45661ea4959a944ca2917454d1314546cc0c88537479e00550eef05bed5b1b9 2025-02-27
FileHash-SHA1 e056d93490fc1c8a07745930e763611989eda674 SHA1 of 8187240dafbc62f2affd70da94295035c4179c8e3831cb96bdd9bd322e22d029 2025-02-27
FileHash-SHA1 f26028851f3b6f81c915ee1243173434fad86172 SHA1 of 9f62c1d330dddad347a207a6a565ae07192377f622fa7d74af80705d800c6096 2025-02-27