The sub-techniques beta is now live! Read the release blog post for more info.

HDoor

HDoor is malware that has been customized and used by the Naikon group. [1]

ID: S0061
Associated Software: Custom HDoor
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 31 May 2017
Last Modified: 25 April 2019

Techniques Used

Domain ID Name Use
Enterprise T1089 Disabling Security Tools

HDoor kills anti-virus found on the victim.[1]

Enterprise T1046 Network Service Scanning

HDoor scans to identify open ports on the victim.[1]

Groups That Use This Software

ID Name References
G0019 Naikon [1]

References