Nightdoor — Malware Profile
Nightdoor is a backdoor exclusively associated with Daggerfly operations. Nightdoor uses common libraries with MgBot and MacMa, linking these malware families together.
MITRE ATT&CK techniques (14)
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1071 Application Layer Protocol
- T1082 System Information Discovery
- T1102 Web Service
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 System Checks
- T1574 Hijack Execution Flow
- T1680 Local Storage Discovery