Backdoor
A backdoor is a hidden way in. Once placed or opened, it lets the attacker return to the machine — with no password, no authorization and no entry in the ordinary records. A backdoor can be opened by malware while it runs, but it can equally be a user account nobody watches, or web shell access left on a server.
Term
description · examples · notesA backdoor is a hidden way in. Once placed or opened, it lets the attacker return to the machine — with no password, no authorization and no entry in the ordinary records. A backdoor can be opened by malware while it runs, but it can equally be a user account nobody watches, or web shell access left on a server.
Description
The attacker usually plants it after the first break-in, to secure a way back even when the main entrance is closed. Sometimes it is left behind by employees or service providers, deliberately or by accident. Sometimes it surfaces as a software or hardware vulnerability. It always serves the same purpose — permanent access to the victim's machine or network, regardless of patching, changed credentials or a reinstalled system.
Blocking the initial way in is not the end of the fight. Until you establish which backdoor was opened during the attack, the job is not finished.
Examples
- After the break-in, the attacker creates an administrator account nobody notices; the IT team patches the vulnerability the infection came through, but the hidden account lets the attacker back.
- A web shell is placed on a ministry's web server — a script that runs on its own and gives the attacker remote control. The access lasts for months without anyone suspecting anything.
- A contractor maintaining a local company's network leaves themselves remote access, just in case. The contract expires; the access stays.
Notes
- Closing the door the attacker came through is not the same as closing the one they left behind.
- A backdoor is rarely the work of exotic malware and most often a banal oversight: one administrative account too many, an ancient vulnerability, a forgotten supplier's access, a script nobody can account for.
Mentioned in the news
- 1. MAJ 2026. FIRESTARTER backdoor kompromitovao Cisco Firepower uređaj američke agencije →
- 28. APR 2026. Firestarter backdoor može da preživi zakrpe na Cisco uređajima →
- 28. APR 2026. Zaraženi Cisco firewall uređaji traže hladni start za uklanjanje Firestartera →
- 24. APR 2026. GopherWhisper cilja mongolske državne sisteme Go backdoor alatima →
- 28. MAR 2026. Red Menshen koristi BPFDoor za prikriveno prisustvo u telekom mrežama →
- 18. FEB 2026. Novi Keenadu backdoor pronađen u Android firmware-u i Google Play aplikacijama →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 18. JUN 2026. Kada su na meti istraživanja, Kina cilja medicinu, AI i vojni sektor →
- 1. MAJ 2026. PhantomCore zloupotrebljava TrueConf ranjivosti za upade u ruske mreže →
- 4. APR 2026. Kineska grupa TA416 gađa evropske vlade PlugX malwareom i OAuth phishingom →
- 2. APR 2026. Napad na Axios ubacio zlonamernu zavisnost u široko korišćeni npm paket →
- 2. APR 2026. Google pripisao napad na axios npm paket severnokorejskoj grupi UNC1069 →
- 4. MAR 2026. Kako piratski softver pretvara zaposlene u distributere malvera →
Techniques
carried out with 14Techniques used to carry it out. Select one to open its page.
Defenses
countered by 12How it is defended against. Select one to open its page.