Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Merdoor Backdoor Exploits Agencies By The Lancefly APT
News & Analysis Attacks Malware Threat Intelligence Threats and Vulnerabilities

Merdoor Backdoor Exploits Agencies By The Lancefly APT

Olivia WilliamBy Olivia WilliamMay 15, 2023Updated:August 20, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Merdoor Backdoor Exploits Agencies By The Lancefly APT
Merdoor Backdoor Exploits Agencies By The Lancefly APT
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

South and Southeast Asian government, airline, and telecom institutions have been targeted by a new APT hacking outfit called Lancefly, which employs a variant of the ‘Merdoor’ backdoor malware.

Symantec Threat Labs announced today that Lancefly has been using the stealthy Merdoor backdoor in targeted attacks against businesses since 2018. This allows the attackers to remain persistent, issue instructions, and collect keystroke data.

According to the latest Symantec research, “Lancefly’s bespoke malware, which we have termed Merdoor, is a formidable backdoor that looks to have existed since 2018.

Researchers at Symantec saw it in action in 2020 and 2021, and this latest campaign carried on until the first quarter of 2023. Intelligence gathering is assumed to be the driving force behind both of these efforts.

According to experts, Lancefly is primarily interested in cyber-espionage and plans to spend a long time gathering data from the networks of its victims.

The primary infection vector utilized by Lancefly has not yet been found by Symantec. However, over time, it has discovered evidence that the threat organization exploits public-facing server vulnerabilities, SSH credentials, and phishing emails to gain unauthorized access.

After gaining access to the victim’s machine, attackers inject the Merdoor backdoor through DLL side-loading into either ‘perfhost.exe’ or’svchost.exe,’ both of which are legal Windows processes that the malware can use to avoid detection.

By installing itself as a service that stays in place even after a system reboot, Merdoor makes it easier for Lancefly to keep a footing on the victim’s machine.

Merdoor connects to the C2 server through one of the several available protocols (HTTP, HTTPS, DNS, UDP, and TCP) and waits for commands.

Symantec’s experts have not offered any examples. However, Merdoor can take commands via listening on local ports in addition to facilitating data interchange with the C2 server.

The keystrokes of the user are also recorded by the backdoor, which could be used to steal sensitive data.

SMB traffic analysis has revealed that Lancefly makes use of the ‘Atexec’ capability of Impacket to quickly launch a predetermined task on a remote machine. It is thought that the threat actors are utilizing this function to either remove output files generated by other commands or to afterward spread to other devices on the network.

Attackers try to get their hands on credentials by stealing them from the SAM and SYSTEM registry hives or dumping the memory of the LSASS process. Finally, Lancefly uses a fake version of the popular WinRAR archiver to encrypt stolen files before removing them, perhaps with Merdoor.

It was also discovered that the ZXShell rootkit was being used in Lancefly assaults, but a newer, lighter, and more feature-rich version was being used.

“FormDII.dll,” the rootkit’s loader, exports features that can be used to drop payloads tailored to the host’s system architecture, read and execute shellcode from a file, terminate processes, and more.

Lancefly’s use of code reuse is evident in the fact that the rootkit relies on an update and installation tool that shares code with the Merdoor loader.

ZXShell can be installed with features that allow it to create, hijack, and run services; modify the registry; and compress a copy of its executable for hiding and protection.

Lancefly shares certain similarities with other Chinese APT groups, like APT17 and APT41, due to their usage of the ZXShell rootkit. The rootkit’s source code has been freely available for years, though, making the connection weak.

The rootkit loader for Lancefly has been reported before in an APT27, called “Budworm,” campaign under the name “formdll.dll.” It is not apparent, however, if this was done on purpose to throw off analysts and make attribution more difficult.

The use of the PlugX and ShadowPad RATs (remote access trojans), which are shared by multiple Chinese APT organizations, lends support to the theory that Lancefly originated in China.

Conclusion

Organizations in South and Southeast Asia have been the target of attacks by the advanced persistent threat (APT) group Lancefly, which has been seen using a custom-written backdoor in their operations. New information from Symantec’s Threat Hunter Team indicates that these attacks have been going on for years. According to a warning released by the company earlier today, “Lancefly’s custom malware, which we have dubbed Merdoor, is a powerful backdoor that appears to have existed since 2018.” Researchers at Symantec noticed its use in a campaign that began in the first quarter of 2023 and persisted through the first half of that year. Intelligence gathering is assumed to be the driving force behind both of these efforts.

Research intelligence-gathering organizations more thoroughly by reading: Cranefly Attackers Employ Covert Methods to Spread Malware Symantec stated that the backdoor has only been seen on a small number of networks and PCs over the years, suggesting that it has been used selectively. An upgraded version of the ZXShell rootkit would also be available to the attackers in this campaign. The most current effort, which Symantec says began in the middle of 2022 and will continue into 2023, is focused on South and Southeast Asian targets in the governmental, aviation, educational, and telecommunications sectors, among others.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}