{"id":2588,"date":"2021-05-04T21:04:03","date_gmt":"2021-05-05T02:04:03","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2588"},"modified":"2021-05-04T21:04:03","modified_gmt":"2021-05-05T02:04:03","slug":"portdoor-the-backdoor-malware-targeting-russia","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/","title":{"rendered":"PortDoor, the backdoor malware targeting Russia"},"content":{"rendered":"\n<p>The RoyalRoad tool was seen to obtain the unique PortDoor sample once the malicious RTF document was opened, which researchers say was designed with stealth in mind. It has multiple functionalities including the ability to perform reconnaissance, target profiling, delivery of additional payloads, privilege escalation, process manipulation, static detection antivirus evasion, one-byte XOR encryption, exfiltration of AES-encrypted data, and more.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the PortDoor attack was carried out <\/h2>\n\n\n\n<p>Hackers, suspected of working for the Chinese government, have used a new malware called PortDoor to infiltrate the systems of an engineering company that designs submarines for the Russian Navy. They used a spear-phishing email specifically crafted to entice the CEO of the company to open a malicious document.<\/p>\n\n\n\n<p>The attack started with shipowner RoyalRoad, also known as the 8.t Dropper \/ RTF exploit generator, a tool that Cybereason said is part of the arsenal of several Chinese APTs, such as Tick, Tonto Team and TA428. RoyalRoad generates armed RTF documents that exploit vulnerabilities in Microsoft&#8217;s Equation Editor (CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802).<\/p>\n\n\n\n<p>The use of RoyalRoad is one of the reasons the company believes that Chinese cybercriminals are behind the attack. Accumulating evidence, such as infection vector, social engineering style, use of RoyalRoad against similar targets, and other similarities between the newly discovered backdoor sample and other known Chinese APT malware, all bear the stamp of an actor from threats operating on behalf of Chinese state-sponsored interests.<\/p>\n\n\n\n<p>The threat actor was targeting the Central Engineering Design Bureau, Marina Rubin, in St. Petersburg, a defense contractor that designs most of Russia&#8217;s nuclear submarines, Cybereason Nocturnus threat researchers discovered that the attacker lured the recipient to open the malicious document with an overview of an autonomous underwater vehicle.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/\">Vollgar \u2013 Malware that is launched with brute force<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/what-variants-of-trojans-can-we-find-on-the-internet\/\">What variants of Trojans can we find on the Internet?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The RoyalRoad tool was seen to obtain the unique PortDoor sample once the malicious RTF document was opened, which researchers say was designed with stealth in mind. It has multiple functionalities including the ability to perform reconnaissance, target profiling, delivery of additional payloads, privilege escalation, process manipulation, static detection antivirus evasion, one-byte XOR encryption, exfiltration [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2589,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2588","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-05T02:04:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"PortDoor, the backdoor malware targeting Russia\",\"datePublished\":\"2021-05-05T02:04:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/\"},\"wordCount\":313,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/malwr.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/\",\"name\":\"PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/malwr.jpg\",\"datePublished\":\"2021-05-05T02:04:03+00:00\",\"description\":\"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/malwr.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/malwr.jpg\",\"width\":640,\"height\":350,\"caption\":\"Robot hand pressing virtual button with online security and warning virus malware.AI(artificial intelligence) hand touching warning malware sign on screen laptop.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/portdoor-the-backdoor-malware-targeting-russia\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PortDoor, the backdoor malware targeting Russia\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog","description":"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/","og_locale":"es_MX","og_type":"article","og_title":"PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog","og_description":"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....","og_url":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-05T02:04:03+00:00","og_image":[{"width":640,"height":350,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"PortDoor, the backdoor malware targeting Russia","datePublished":"2021-05-05T02:04:03+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/"},"wordCount":313,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/","url":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/","name":"PortDoor, the backdoor malware targeting Russia - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg","datePublished":"2021-05-05T02:04:03+00:00","description":"As we well know, internet threats are present everywhere, and this time a malware called PortDoor targeted a Russian Navy company.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/malwr.jpg","width":640,"height":350,"caption":"Robot hand pressing virtual button with online security and warning virus malware.AI(artificial intelligence) hand touching warning malware sign on screen laptop."},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/portdoor-the-backdoor-malware-targeting-russia\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"PortDoor, the backdoor malware targeting Russia"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2588"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2588\/revisions"}],"predecessor-version":[{"id":2610,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2588\/revisions\/2610"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2589"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}