CrowDoor is a Windows backdoor closely related to SparrowDoor and assessed as a variant within the same malware lineage. It has been observed in cyber-espionage operations linked to multiple China-nexus intrusion clusters, including Tropic Trooper, FamousSparrow-associated activity, Earth Estries, UAT-9244, and reporting that also associates its use with Salt Typhoon-related tradecraft. The malware has been deployed in intrusions against government and telecommunications targets, including campaigns in East Asia, the Middle East, South America, and Southeast Asia.
CrowDoor is typically delivered as a later-stage payload through loader chains and DLL side-loading or search-order hijacking. Reported delivery mechanisms include use of SparrowDoor Loader, Draculoader, and malicious side-loaded DLL components that decrypt and execute the payload in memory. In observed attack chains, CrowDoor has also been used alongside Cobalt Strike and other post-exploitation tooling.
The malware supports persistent remote access and flexible execution modes controlled by command-line arguments. It can establish persistence through Windows Registry Run entries or Windows service creation, then restart itself by injecting into a legitimate process, with newer variants noted for using msiexec.exe. Its functionality includes command-and-control communications, remote shell execution, system information collection, and extensive file operations such as reading, writing, searching, renaming, deleting, and drive enumeration. Variants have also supported self-removal by deleting malware components and removing persistence.
CrowDoor demonstrates defense-evasion and post-exploitation tradecraft through in-memory execution, process injection, encrypted or obfuscated components, and use of legitimate host processes and side-loading packages. Multiple reports note structural and command-level overlap with SparrowDoor, shared loader shellcode, and continued variant development, including TernDoor as a later CrowDoor-derived backdoor. Overall, CrowDoor is best characterized as a modular espionage backdoor used after initial compromise to maintain access, execute operator commands, and support collection and follow-on intrusion activity on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This attack chain was attempting to load the Crowdoor loader, which is half-named after the SparrowDoor backdoor... The malicious samples are called Crowdoor, which, when run, drop CobaltStrike and maintain persistence.
This attack chain was attempting to load the Crowdoor loader, which is half-named after the SparrowDoor backdoor... The malicious samples are called Crowdoor, which, when run, drop CobaltStrike and maintain persistence.
A variant of Crowdoor (itself a variant of SparrowDoor), the backdoor is said to have been put to use by UAT-9244 since at least November 2024.
TernDoor is a variant of CrowDoor, a backdoor deployed in recent intrusions linked to China-nexus APTs such as FamousSparrow and Earth Estries. CrowDoor is a variant of SparrowDoor...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"However, in some instances, WMIC may be used in its place to achieve similar results."
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2”... The main loading functionality was designed to execute a legitimate msiexec.exe process, then inject the next stage by writing into its remote address space and creating a remote thread to execute it.
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2”... The main loading functionality was designed to execute a legitimate msiexec.exe process, then inject the next stage by writing into its remote address space and creating a remote thread to execute it.
This function implements the main functionality for this loader, decrypting the shellcode for the next stage from a memory buffer inside the datastate.dll file using a variant of the RC4 stream cipher.
When executed, it injects itself into the colorcpl.exe process with the command-line argument “2” and tries to contact a C2 server that is hardcoded in the payload using its configuration (blog.techmersion[.]com on port 443).
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload delivered by Draculoader.
Referenced as a related backdoor family (variant lineage: Crowdoor -> SparrowDoor) used for comparison with TernDoor; specific functional details are not provided beyond its relationship/overlap.
Windows backdoor family (and a SparrowDoor variant) used in China-nexus intrusions; TernDoor is described as a newly observed variation with different command codes and an embedded encrypted driver for process control/evasion.
Backdoor that persists via Run-key registry modification and/or Windows service creation; supports process injection (e.g., into msiexec.exe) and encrypted C2 communications with command/tasking capabilities (file ops, remote shell, etc.).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.