DoorMe
- First seen
- 2013-01-15 00:00:00
- Malware type
- rat, webshell
- Profile updated
- 2026-07-07 13:05:08
Targeted industries: government-and-public-sector defense-and-aerospace
Context
DoorMe is a remote access tool and webshell utilized primarily for cyber espionage activities. It enables attackers to gain persistent access to compromised systems, often used in targeted attacks against government and defense sectors.
Detection coverage
- 1 YARA rules
Used by threat actors
- Chamelgang (threat-actor)
Detection rules
- MALPEDIA_Win_Doorme_Auto (yara-rule)
Reports & references
- ptsecurity.com — New Apt Group Chamelgang (report)
- hitcon.org — Unmasking%20Camofei An%20In Depth%20Analysis%20Of%20An%20Emerging%20Apt%20Group%20Focused%20On%20Healthcare%20Sectors%20In%20East%20Asia (report)
- stillu.cc — 2023 08 Unmasking%20Camofei (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Doorme (report)
- elastic.co — Siestagraph New Implant Uncovered In Asean Member Foreign Ministry (report)
- elastic.co — Update To The Ref2924 Intrusion Set And Related Campaigns (report)