🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
A backdoor attack is a cyberattack in which an attacker creates or exploits a hidden access point to enter a system, network, or application without passing normal authentication. This hidden access bypasses login checks, security monitoring, and user awareness, letting attackers move in and out of a system without detection.
Unlike attacks built for immediate disruption, a backdoor attack is built for persistence. Once the hidden access point is in place, attackers can return at will to steal data, monitor activity, or stage further attacks without needing to re-exploit the original weakness.
Scale in this category is easy to underestimate from the outside. CloudSEK researchers recovered an exposed directory belonging to one operator and catalogued more than 12,000 WordPress backdoors left across compromised sites, alongside harvested credentials and wallet keys. A single operator, running AI coding agents on full auto, held persistent access to thousands of systems whose owners had no idea.
The lifecycle stays consistent whichever entry point the attacker uses. Each stage exists to make the next one unnecessary to repeat.

Remediation breaks down at stage three more reliably than at any other point. Removing the malware that delivered the backdoor does nothing to the scheduled task, service, or account it created, and the attack path reopens the moment anyone assumes the incident is closed.
Backdoor design assumes that somebody will eventually come looking for it. Every property below exists to delay or defeat that inspection.
Classification follows the layer a backdoor occupies, because position determines how it gets found and how hard removal becomes.

Malware delivers these after infecting a system, opening a command-and-control channel for remote execution, data theft, and further payload delivery. Most include persistence routines so the implant survives a restart. They remain the most common form and the most likely to be caught, since malware families eventually pick up signatures.
Hidden inside software that looks legitimate, including cracked applications, fake updates, and malicious attachments. Installation activates the backdoor silently. Perceived trustworthiness of the carrier gets it past the user, not any technical evasion.
A malicious script uploaded to a web server provides command execution, file manipulation, and database access through ordinary HTTP requests. Insecure upload functions, unpatched application flaws, and weak administrative credentials all create the opening. Web shells are the highest-volume backdoor type by a wide margin, because the target set is every exposed web application on the internet, and most of it falls outside anyÂ
These modify core system components: services, startup processes, registry entries, scheduled tasks, or privileged accounts. Integration into the operating system gives deep, elevated access that routine scans and updates rarely disturb.
Implants below the operating system, in BIOS or UEFI firmware, network device firmware, or embedded hardware. These survive disk formatting and full reinstallation. They are rare, and remediation means replacing the device in many cases.
Infrastructure moved to cloud and container platforms, and the techniques followed it there. Misconfigured IAM roles, hidden service accounts, and long-lived access keys create persistence in cloud environments. Malicious layers baked into container images survive every redeployment of that image.
OAuth token abuse deserves separate attention from everything else in this list. A retained token or an approved third-party application grant keeps working through password resets and MFA enrollment, because neither action revokes it. Endpoint tooling has no visibility into any of it.
These terms get used interchangeably because the techniques appear together in the same intrusions. Purpose is the distinction that matters. A backdoor exists to guarantee re-entry, not to execute, conceal, or coordinate.
Backdoor activity maps to several MITRE ATT&CK tactics, not to a single technique. Mapping observed behavior to these tactics tells a team which telemetry source will actually hold the evidence.
These four cases cover the range, from a build-system compromise caught by accident to nation-state persistence that ran undetected for months.
An operator spent nearly two years contributing to the xz compression project until they were granted maintainer rights, then inserted a backdoor into release tarballs for versions 5.6.0 and 5.6.1. The malicious code never appeared in the source repository. It was extracted from a disguised test file during the build and hooked into sshd authentication through liblzma. Tracked as CVE-2024-3094 at CVSS 10.0, it was caught only because an engineer investigated a half-second delay in SSH logins. That supply chain attack came close to reaching every major Linux distribution.
A nation-state actor inserted backdoor code into signed Orion software updates, reaching government agencies and large enterprises worldwide. The implant waited before activating and communicated through traffic shaped to resemble normal product telemetry. It remains the reference case for why signed updates from a trusted vendor are not self-validating, and why advanced persistent threat campaigns are defined by patience rather than technique.
Attackers exploited Exchange Server vulnerabilities and dropped web shells on thousands of organizations. Patching closed the vulnerability and left the web shells running, which produced a second wave of compromise among organizations that believed they had remediated.
CloudSEK's analysis of the exposed operator directory described above documented backdoors across thousands of compromised sites, catalogued in 142,262 files. AI coding agents ran the intrusion work in full-auto mode with approvals disabled. Scale of this kind is now achievable by a single operator.
Detection difficulty shows up most clearly in the published dwell-time figures. Mandiant's M-Trends 2026 analysis, covering more than 500,000 hours of incident response, put the global median attacker dwell time at 14 days for 2025. Espionage-motivated intrusions, where long-term backdoor access is the objective and not a side effect, ran to a median of 122 days.
Several obstacles account for most of that gap in day-to-day practice.
Detection works through correlation over time, not through any single alert. These signals matter most, ordered roughly by how reliably each produces a confirmed finding.
Threat hunting closes whatever gap the alerting layer leaves behind. Querying telemetry proactively against persistence and command-and-control techniques finds implants that generated no alert at all, which is the normal outcome for a well-built backdoor and a recurring theme across current threat activity.
Response order matters more here than in most incidents, because premature cleanup destroys the evidence needed to find the second backdoor.
Prevention splits between reducing the chance of initial compromise and reducing what persistence achieves once it exists.
The 12,000 backdoors in that operator's directory were not planted on monitored corporate endpoints. They sat on public websites, most of them running on infrastructure whose owners had stopped paying attention. Web shells reach that scale because the target list is every exposed application on the internet, and the owner is the last to find out. CloudSEK BeVigil scans internet-facing web applications, APIs, and infrastructure from the outside, which is the only vantage point that covers assets no internal agent was ever installed on.
No. A backdoor is an access mechanism, not a self-replicating program. A virus or trojan can install one, and the backdoor itself does not spread.
Partially. Signature detection catches known backdoor families. Custom implants and living-off-the-land techniques need EDR, behavioral analytics, and network monitoring.
Yes, at the firmware level. BIOS, UEFI, and device firmware implants persist through reinstallation. Software backdoors do not survive a clean rebuild.
Months in espionage cases. Median dwell time across all intrusion types is far shorter, and backdoors built for long-term access sit at the high end.
Financial services, technology, government, and healthcare, because each holds data whose value justifies maintaining access over long periods.
No. Credentials were accessible for the whole dwell period, and a second persistence mechanism is present in most competent intrusions.
