MicroBackdoor is a Windows backdoor used in espionage-oriented intrusion activity and observed in campaigns targeting Ukraine, including operations associated with UNC1151/UAC-0051 and UAC-0057. It has also appeared as a secondary payload alongside HelloXD ransomware, where it likely serves to preserve attacker access after ransomware deployment.
The malware provides remote access functions that enable operators to browse the file system, upload and download files, execute commands, and uninstall itself. Reported command support includes host identification and system information collection, command execution, shell access, file listing, file retrieval, file upload, update and uninstall functions, and in at least one observed variant, screenshot capture. These features make it suitable for post-compromise control, reconnaissance, and data handling on infected hosts.
Observed delivery chains include spearphishing archives containing malicious CHM and script-based droppers that decode a .NET loader and then execute MicroBackdoor. In one documented infection flow, the loader established persistence through startup execution and abuse of Windows scripting and .NET utilities before launching the backdoor. Separate reporting linked MicroBackdoor to HelloXD ransomware as an embedded secondary payload installed as a service in some variants.
MicroBackdoor has been used against Ukrainian critical information infrastructure and other organizations of strategic interest during the Russia-Ukraine conflict. Its repeated association with UNC1151-linked activity and its use in targeted intrusion chains indicate a role as a lightweight access tool for sustained compromise and operator-controlled actions on victim systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
What is peculiar about this file is it is a variant of the open-source MicroBackdoor, a backdoor allowing an attacker to browse the file system, upload and download files, execute commands and remove itself from the system.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
домен, що використовується сервером управління... xbeta[.]online:8443 ... Серверна частина ... надає простий веб-інтерфейс для управління ботами.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor component referenced as present in known HelloXD versions but absent from the observed sample.
An open-source backdoor deployed by one HelloXD sample as a secondary payload. It provides file browsing, upload/download, command execution, and self-removal, and was likely used to maintain access or monitor victim systems during ransomware operations.
Backdoor malware delivered via spearphishing, with ZIP archive, CHM dropper, and JS dropper artifacts listed as IOCs.
A backdoor associated with UAC-0051/UNC1151 in attacks on Ukrainian infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.