Skip to content
tag — backdoor

grep -rl "backdoor" ./articles

#backdoor

7 articles

The WordPress backdoor lives in eight places at once, and each one rebuilds the others

2026-10-02Security

Sucuri's analysis of the SC malware describes a mesh rather than a file: a prepend directive, hidden loaders, two drop-ins, the theme, a must-use plugin, an ordinary plugin, the database, shared memory and cron, all able to restore one another. Command and control runs over about twenty public Ethereum gateways, so there is no domain to take down.

Adobe has patched StyleSmuggler. The first confirmed victim was fully patched too

2026-09-08Security

CVE-2026-75650 is rated CVSS 10.0 and Adobe shipped the fix on 8 September, four days into active exploitation. Applying it is only half the remediation — the encryption keys have to be rotated as well. And the first confirmed victim was already running the August patches, which is why patching is not the same as being clear.

The backdoor was compiled into HAProxy. That is not an HAProxy vulnerability

2026-09-06Security

Rapid7 found a Linux implant built into the HAProxy binaries of two South Korean organisations, intercepting traffic and erasing its own requests from the proxy's own logs. Every headline calls it an HAProxy backdoor. Installing it requires already owning the host, which makes patching HAProxy the one response that changes nothing.

A state-linked backdoor for diplomats, written as a Windows batch file

2026-08-31Security

HOOKEDGE polls webhook.site for command files, runs them, and posts the output back as HTML. No custom infrastructure, no compiled binary, no exotic protocol — a .cmd script and a free service anyone can sign up for. Recorded Future ties it to APT28 with moderate confidence, and says so.

This backdoor never phones home — it waits for a packet, and everything hunting for beacons misses it

2026-08-26Security

Sleepwalker is a Windows backdoor with a 23-instruction custom bytecode language, AES-256-CCM, and no outbound connections at all. It sits dormant until a specially crafted packet arrives. It loads by side-loading through a security vendor's own management agent while pretending to be Microsoft's dpapi.dll — and the researcher who found it says plainly that he cannot name a single victim.