Taidoor — Malware Profile
Taidoor is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on victim networks. Taidoor has primarily been used against Taiwanese government organizations since at least 2010.
MITRE ATT&CK techniques (20)
- T1005 Data from Local System
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1027.013 Encrypted/Encoded File
- T1055.001 Dynamic-link Library Injection
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1112 Modify Registry
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1204.002 Malicious File
- T1547.001 Registry Run Keys / Startup Folder
- T1566.001 Spearphishing Attachment
- T1573.001 Symmetric Cryptography