PhanDoor

First seen
2017-04-01 00:00:00
Malware type
rat, backdoor
Family
Malware family
Profile updated
2026-07-07 15:15:33

Targeted industries: government-and-public-sector education-and-nonprofits

Targeted regions: country_code:vn country_code:kh

Context

PhanDoor is a remote access tool primarily used by threat actors targeting government and educational institutions in Southeast Asia. It is known for its persistence mechanisms and covert communication channels.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Phandoor_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Phandoor (report)
  • global.ahnlab.com — [Ahnlab]Andariel A Subgroup Of Lazarus%20(3) (report)

External references