logo

TiltedTemple__2022__PaloAltoNetworks_SockDetour-Fileless-Socketless-Backdoor_02-24-2022.pdf

ID: 74a307f4-19bb-445e-9a94-b581d568c940

STIX ID: report--74a307f4-19bb-445e-9a94-b581d568c940

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2022-02-25

Last Modified Date: 2022-02-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 describes SockDetour, a stealthy, fileless Windows backdoor used by the TiltedTemple APT campaign to maintain persistence and control by hijacking legitimate service ports and communicating with a remote operator over encrypted channels; the report links SockDetour to exploitation of ManageEngine vulnerabilities and compromised NAS devices, notes several targeted U.S. defense contractors, and indicates the tool has likely been in the wild since 2019.