logo

YiBackdoor: Linked to IcedID and Latrodectus

ID: 06a221d7-a14b-50a8-8c31-9dfe3e02400a

STIX ID: report--06a221d7-a14b-50a8-8c31-9dfe3e02400a

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-09-26

Date Updated: 2026-05-01

...
...

This technical analysis describes YiBackdoor, a Windows backdoor that employs anti-analysis checks, remote process injection via RtlExitUserProcess hooking, registry Run-key persistence (using randomized names), encrypted embedded configuration, dynamic TripleDES-based network encryption keyed by day-of-week offsets, an HTTP(S) JSON command-and-control channel exposing multiple remote commands (system info, screenshot, shell/PowerShell execution, plugin management), and an extensible encrypted plugin system; the report also documents notable code overlaps with IcedID and Latrodectus suggesting shared code or lineage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.