TiltedTemple__2022__PaloAltoNetworks_SockDetour-Fileless-Socketless-Backdoor_02-24-2022.pdf
ID: 74a307f4-19bb-445e-9a94-b581d568c940
STIX ID: report--74a307f4-19bb-445e-9a94-b581d568c940
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2022-02-25
Last Modified Date: 2022-02-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 describes SockDetour, a stealthy, fileless Windows backdoor used by the TiltedTemple APT campaign to maintain persistence and control by hijacking legitimate service ports and communicating with a remote operator over encrypted channels; the report links SockDetour to exploitation of ManageEngine vulnerabilities and compromised NAS devices, notes several targeted U.S. defense contractors, and indicates the tool has likely been in the wild since 2019.
