logo

New Backdoor, MadMxShell

ID: 80f4bf52-7abe-5465-9705-41829fb093b3

STIX ID: report--80f4bf52-7abe-5465-9705-41829fb093b3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a multi-stage backdoor (MadMxShell) delivered via a trojanized Advanced-ip-scanner executable that sideloads a large IVIEWERS.dll to inject and run a compressed/encrypted payload; the chain drops a OneDrive.exe and Secur32.dll pair which are used to persist and launch stage shellcode that disables Defender, performs process hollowing, and provides a remote backdoor. The backdoor generates session and victim IDs, supports file operations and remote command execution via cmd.exe, and exfiltrates/receives commands through encoded DNS MX queries to litterbolo.com using a custom 36-character encoding and packetization scheme.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.