Andardoor

Aliases: ROCKHATCH

First seen
2017-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:44:36

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ru country_code:ua

Context

Andardoor, also known as ROCKHATCH, is a backdoor malware associated with cyber espionage activities, particularly targeting government and defense entities in Eastern Europe. It is known for providing persistent remote access to compromised systems.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Backdoor_Win_Andardoor (yara-rule)
  • MALPEDIA_Win_Andardoor_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Andardoor (report)
  • asec.ahnlab.com — 56256 (report)
  • asec.ahnlab.com — 56405 (report)
  • asec.ahnlab.com — 47751 (report)

External references