Rifdoor
MITRE ATT&CK: S0433 View on attack.mitre.org
Aliases: Rifdoor
- First seen
- 2019-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:54:13
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.
Detection coverage
- 1 YARA rules
- 149 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- System Information Discovery (attack-pattern)
- Binary Padding (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Malicious File (attack-pattern)
Used by threat actors
- Andariel (threat-actor)
Detection rules
- MALPEDIA_Win_Rifdoor_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- issuemakerslab.com — Research3 (report)
- carbonblack.com — Vmware Carbon Black Tau Threat Analysis The Evolution Of Lazarus (report)
- global.ahnlab.com — [Ahnlab]Andariel A Subgroup Of Lazarus%20(3) (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rifdoor (report)
- mega.nz — Lkh1Gy5C (report)
- MITRE ATT&CK — S0433 (report)