DohDoor

Last reviewed:

DohDoor is a type of malware that uses the Domain Name System (DNS) over HTTPS (DoH) protocol to communicate with its command and control (C2) servers. This approach allows it to bypass traditional security measures that monitor DNS traffic. DohDoor is primarily used for covert communication and data exfiltration. As of October 2023, cybersecurity researchers continue to study its behavior and impact, focusing on its unique use of the DoH protocol to evade detection.

Overview

DohDoor is a malware strain that leverages the DNS over HTTPS (DoH) protocol to establish secure and covert communication channels with its command and control (C2) servers. This method allows it to bypass traditional security mechanisms that monitor DNS traffic, making it challenging to detect and mitigate. DohDoor is primarily used for data exfiltration and maintaining persistent access to compromised systems.

History

The first reports of DohDoor emerged in the cybersecurity community in 2022. Researchers identified its unique use of the DoH protocol, which was relatively uncommon in malware at the time. This innovative approach attracted significant attention from cybersecurity experts and organizations, to increased efforts to understand and combat this threat.

Technical characteristics

DohDoor is characterized by its use of the DNS over HTTPS (DoH) protocol for communication with its command and control (C2) servers. This protocol encrypts DNS queries, making it difficult for traditional security tools to monitor and block malicious traffic. DohDoor typically operates as a backdoor, allowing attackers to execute commands remotely and exfiltrate data from compromised systems.

The malware is designed to be lightweight and modular, enabling it to adapt to different environments and evade detection. It often employs various obfuscation techniques to conceal its presence and functionality, further complicating efforts to analyze and mitigate its impact.

Infection vector

DohDoor is typically distributed through phishing emails, malicious attachments, and compromised websites. Attackers often use social engineering tactics to trick users into downloading and executing the malware. Once installed, DohDoor establishes a connection with its command and control (C2) servers using the DoH protocol, allowing attackers to maintain persistent access to the compromised system.

Notable campaigns

As of October 2023, there have been several notable campaigns involving DohDoor. These campaigns have primarily targeted organizations in sectors such as finance, healthcare, and government. Cybersecurity firms have attributed these campaigns to various threat actor groups, although specific attribution remains challenging due to the malware's use of encrypted communication channels.

Detection and mitigation

Detecting DohDoor can be challenging due to its use of the DNS over HTTPS (DoH) protocol, which encrypts its communication with command and control (C2) servers. However, organizations can implement several strategies to mitigate the risk posed by this malware:

  1. Network Monitoring: Implement advanced network monitoring solutions that can detect anomalies in DNS traffic, even when encrypted.
  1. Endpoint Protection: Deploy comprehensive endpoint protection solutions that can identify and block malicious activities associated with DohDoor.
  1. User Education: Educate users about the risks of phishing attacks and the importance of verifying the authenticity of emails and attachments.
  1. Patch Management: Regularly update software and systems to address vulnerabilities that could be exploited by DohDoor.
  1. Threat Intelligence: Leverage threat intelligence feeds to stay informed about the latest tactics, techniques, and procedures (TTPs) used by threat actors deploying DohDoor.

By implementing these measures, organizations can reduce the risk of infection and limit the impact of DohDoor on their networks.

DohDoor Malware Communication Flow

DohDoor Malware History

See also

Sources

Categories: Malware
Last updated: October 7, 2026