DoorMe is a Windows backdoor implemented as a malicious native C++ module for Microsoft Internet Information Services (IIS). It provides covert remote access to compromised web servers, including Microsoft Exchange servers, by intercepting incoming HTTP requests before normal IIS processing. The module remains passive until a request supplies a specific authentication value in an HTTP cookie. Authenticated GET requests can return the host's username and hostname, while POST requests carry AES-encrypted commands encoded with a customized Base64 alphabet.
DoorMe supports generating an identifier for an infected system, receiving and reassembling shellcode in chunks, and executing shellcode in memory within its hosting process. It communicates with executing shellcode through named pipes to deliver input and retrieve output. Its anti-analysis features include XOR-obfuscated strings, control-flow flattening, anti-disassembly techniques, and runtime API resolution. Loading within IIS provides an embedded foothold in the web-server infrastructure rather than relying on a standalone executable.
DoorMe has been used by ChamelGang and in activity tracked as REF2924. ChamelGang deployed a modified DoorMe v2 on Exchange servers at a Russian aviation organization after exploiting the ProxyShell vulnerability chain, comprising CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. Other observed deployments affected the foreign ministry of an ASEAN member state and a telecommunications provider in Afghanistan. These deployments place DoorMe in operations targeting aviation, government, diplomatic, and telecommunications environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attackers then installed a modified version of the backdoor DoorMe v2 on two Microsoft Exchange mail servers on the victim’s network.
DOORME is a native backdoor module that is loaded into a victim's IIS infrastructure and used to provide remote access to the target infrastructure.
The deployment method for malicious IIS modules like DOORME can be found in a referenced blog post.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
DOORME XOR-encrypts strings to evade detection... The malware also employs... Control Flow Obfuscation (CFO) to complicate the analysis of its behavior.
DOORME first resolves the address of LoadLibraryA and GetProcAddress Windows API by parsing the kernel32.dll module export table.
The IIS backdoor monitored incoming HTTP requests and accepted commands through POST requests; SiestaGraph used Microsoft Graph API C2.
U - Download from OneDrive... the file is downloaded from OneDrive by the implant, but uploaded by the attacker.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another malware example observed using control-flow flattening obfuscation.
Mentioned only as another malware example in which control-flow flattening was observed.
A named implant/tool previously observed in the REF2924 intrusion set.
Previously observed malware in the same government victim environment; no functionality is described here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.