Skip to main content

RGDoor Backdoor

A new backdoor has been discovered that targets Internet Information Services (IIS) servers, allowing an attacker to compromise a web server.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new backdoor has been discovered that targets Internet Information Services (IIS) servers, allowing an attacker to compromise a web server.

Threat details

Previously accessing these web servers was inaccessible but due to the TwoFace webshell this attack vector allows an attacker to remotely access the server.

RGDoor is implemented as a secondary backdoor, produced in C++ the backdoor results in a Dynamic Link Library (DLL). The DLL has a function called RegisterModule which allows an attacker to infer that the DLL was an HTTP module.

When code calls RegisterModule it is done so by ignoring any incoming HTTP GET requests, yet it does not do the same for HTTP POST requests. This will allow an attacker to upload or download files from the target server as well as run commands through the command prompt.


Remediation steps

Type Step
  • Ensure anti-virus is installed on all servers where applicable and that it is kept up to date
  • Remove any unrecognised webshells from web servers

Last edited: 17 February 2020 12:53 pm