logo

Squidoor: Suspected Chinese Threat Actor’s Backdoor Targets Global Organizations

ID: a677eae6-fc00-590e-b173-f59d5f8ba365

STIX ID: report--a677eae6-fc00-590e-b173-f59d5f8ba365

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-02-27

Date Updated: 2026-04-28

Author: Lior Rochberger and Tom Fakterman

...
...

This Unit 42 report analyzes CL-STA-0049, a suspected Chinese APT campaign using IIS exploits and web shells to deploy a multi-platform stealth backdoor called Squidoor (FinalDraft) across Southeast Asia and South America; Squidoor supports numerous covert C2 methods (including Outlook API, DNS and ICMP tunneling), performs in-memory code injection and lateral movement, and the report provides detailed TTPs, IOCs (file hashes, domains, IPs) and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.