Taidoor
MITRE ATT&CK: S0011 View on attack.mitre.org
Aliases: simbot, Taidoor
- First seen
- 2010-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 17 (14 malicious)
- Last IoC activity
- 2026-09-01 07:30:48
- Profile updated
- 2026-07-07 12:56:16
Targeted industries: government-and-public-sector
Targeted regions: country_code:tw
Context
Taidoor is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on victim networks. Taidoor has primarily been used against Taiwanese government organizations since at least 2010.
Recent IoC activity
14 malicious indicators in Maltiverse are attributed to Taidoor (S0011). The 14 most recently updated:
Detection coverage
- 1 YARA rules
- 391 Sigma rules
Malware & tools used
- System Time Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Modify Registry (attack-pattern)
- Web Protocols (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Native API (attack-pattern)
- File Deletion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Query Registry (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Data from Local System (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Malicious File (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
Exploited vulnerabilities
- CVE-2010-3333 (vulnerability)
Detection rules
- MALPEDIA_Win_Taidoor_Auto (yara-rule)
Reports & references
- trendmicro.de — Wp The Taidoor Campaign (report)
- blog.reversinglabs.com — Taidoor A Truly Persistent Threat (report)
- web.archive.org — Globalthreatintelreport (report)
- macnica.net — Mpressioncss Ta Report 2019 (report)
- macnica.net — Mpressioncss 2018 1H Report Mnc Rev3 Nopw (report)
- Trend Micro — Wp Detecting Apt Activity With Network Traffic Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Taidoor (report)
- contagiodump.blogspot.com — Sep 28 Cve 2010 3333 Manuscript With (report)
- CISA — Ar20 216A (report)
- Mandiant — Evasive Tactics Taidoor 3 (report)
- nttsecurity.com — Taidoor%E3%82%92%E7%94%A8%E3%81%84%E3%81%9F%E6%A8%99%E7%9A%84%E5%9E%8B%E6%94%Bb%E6%92%83%E8%A7%A3%E6%9E%90%E3%83%Ac%E3%83%9D%E3%83%Bc%E3%83%88 V1 (report)
- Trend Micro — Wp The Taidoor Campaign (report)
- MITRE ATT&CK — S0011 (report)