DoorMe

First seen
2013-01-15 00:00:00
Malware type
rat, webshell
Profile updated
2026-07-07 13:05:08

Targeted industries: government-and-public-sector defense-and-aerospace

Context

DoorMe is a remote access tool and webshell utilized primarily for cyber espionage activities. It enables attackers to gain persistent access to compromised systems, often used in targeted attacks against government and defense sectors.

Detection coverage

  • 1 YARA rules

Used by threat actors

Detection rules

  • MALPEDIA_Win_Doorme_Auto (yara-rule)

Reports & references

  • ptsecurity.com — New Apt Group Chamelgang (report)
  • hitcon.org — Unmasking%20Camofei An%20In Depth%20Analysis%20Of%20An%20Emerging%20Apt%20Group%20Focused%20On%20Healthcare%20Sectors%20In%20East%20Asia (report)
  • stillu.cc — 2023 08 Unmasking%20Camofei (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Doorme (report)
  • elastic.co — Siestagraph New Implant Uncovered In Asean Member Foreign Ministry (report)
  • elastic.co — Update To The Ref2924 Intrusion Set And Related Campaigns (report)

External references