Misdat is a Windows backdoor associated with targeted intrusion activity. It has been observed masquerading as a legitimate Microsoft component by saving itself under the name of the Microsoft Distributed Transaction Coordinator service binary, a tactic intended to reduce suspicion. Samples have commonly been packed with UPX, and many were developed in Borland Delphi, which can result in anomalous PE compile timestamps.
Misdat provides remote shell functionality, allowing an operator to execute commands on a compromised host. It can collect files and other data from the victim and upload the stolen material to command-and-control infrastructure, indicating both collection and exfiltration capability over its established control channel. Its network communications have been observed over raw sockets, with traffic encoded as Base64 plaintext rather than strongly encrypted.
The malware also includes cleanup and anti-forensics behavior. It is capable of deleting its own backdoor file, supporting self-removal or artifact cleanup after operations. In addition, Misdat has attempted to determine whether an infected system uses a Japanese keyboard through the Windows GetKeyboardType API, suggesting victim profiling or execution gating based on regional characteristics.
Overall, Misdat is best characterized as a command-execution backdoor for Windows environments with file collection, exfiltration, simple traffic obfuscation, masquerading, and self-deletion features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware whose PE compile timestamps may appear altered due to Borland Delphi compilation artifacts.
Malware that masquerades as the legitimate msdtc.exe Windows binary.
Backdoor malware capable of deleting its backdoor file.
Malware whose network traffic is Base64-encoded plaintext.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.