PhanDoor
- First seen
- 2017-04-01 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 15:15:33
Targeted industries: government-and-public-sector education-and-nonprofits
Targeted regions: country_code:vn country_code:kh
Context
PhanDoor is a remote access tool primarily used by threat actors targeting government and educational institutions in Southeast Asia. It is known for its persistence mechanisms and covert communication channels.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Phandoor_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Phandoor (report)
- global.ahnlab.com — [Ahnlab]Andariel A Subgroup Of Lazarus%20(3) (report)