cd00r

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[cd00r](https://attack.mitre.org/software/S1204) is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000. [cd00r](https://attack.mitre.org/software/S1204) source code is primarily based on a packet-capturing program as it utilizes a sniffer to listen for specific sequences of network traffic or "secret knock" before executing the attacker's code.(Citation: Hartrell cd00r 2002)(Citation: Lumen J-Magic JAN 2025)

Associated Techniques (4)
ID ATT&CK Tactics
T1016 System Network Configuration Discovery -
T1040 Network Sniffing -
T1095 Non-Application Layer Protocol -
T1205.001 Port Knocking -
Metadata
ID: 3
Created: 13/01/2026 17:48
Updated: 23/04/2026 04:00