MicroBackdoor is an open-source backdoor used to remotely control compromised Windows systems. It supports system-information collection, filesystem browsing, program and command execution, reverse shells, file uploads and downloads, and self-removal. Modified variants deployed against Ukrainian targets add screenshot capture to the standard command set.
MicroBackdoor has been used by UNC1151 in spearphishing campaigns targeting Ukraine, including activity against critical information infrastructure. Observed delivery chains use ZIP archives containing malicious Compiled HTML Help documents with certificate, COVID-19, or wartime-safety lures. Embedded scripts launch droppers and obfuscated .NET loaders that decode and execute the backdoor in memory. These deployments establish persistence through startup shortcuts and abuse legitimate Windows scripting and .NET utilities for execution.
MicroBackdoor has also been deployed as a secondary payload by HelloXD ransomware. In an observed Windows variant, the ransomware decrypts and drops the backdoor, installs it as a service, and executes it. MicroBackdoor's remote-control and file-transfer capabilities provide operators with continued access to compromised systems independently of the ransomware's encryption functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The in-memory payload is the open-source backdoor MicroBackdoor. It connects to xbeta.online on port 8443 and supports system-information collection, program execution, reverse shells, and file transfers. This sample adds screenshot functionality.
What is peculiar about this file is it is a variant of the open-source MicroBackdoor, a backdoor allowing an attacker to browse the file system, upload and download files, execute commands and remove itself from the system.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
домен, що використовується сервером управління... xbeta[.]online:8443 ... Серверна частина ... надає простий веб-інтерфейс для управління ботами.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor component referenced as present in known HelloXD versions but absent from the observed sample.
An open-source backdoor deployed by one HelloXD sample as a secondary payload. It provides file browsing, upload/download, command execution, and self-removal, and was likely used to maintain access or monitor victim systems during ransomware operations.
Backdoor malware delivered via spearphishing, with ZIP archive, CHM dropper, and JS dropper artifacts listed as IOCs.
A backdoor associated with UAC-0051/UNC1151 in attacks on Ukrainian infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.