Crowdoor Backdoor
Summary
Crowdoor has evolved, functioning not only as a backdoor but also as a loader capable of deploying other threatening tools, including Cobalt Strike, a popular framework used for post-exploitation tasks. The Crowdoor malware grants attackers a high degree of control over compromised systems, allowing them to execute commands remotely, establish reverse shells, and even remove evidence of their presence by deleting other unsafe files. The attack chain that delivers Crowdoor begins with the exploitation of vulnerabilities in publicly accessible Web servers, often those running open-source Content Management Systems (CMS) like Umbraco. Once inside the network, the attackers deploy the Crowdoor backdoor, which acts as both a loader and a persistent threat, enabling the download and execution of additional malware, such as Cobalt Strike, to achieve deeper levels of compromise. In addition to facilitating remote command execution and data exfiltration, Crowdoor has the capability to terminate its own processes, erase other malware files, and evade detection, making it extremely difficult for defenders to identify and neutralize.