Rifdoor

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Rifdoor](https://attack.mitre.org/software/S0433) is a remote access trojan (RAT) that shares numerous code similarities with [HotCroissant](https://attack.mitre.org/software/S0431).(Citation: Carbon Black HotCroissant April 2020)

Associated Techniques (9)
ID ATT&CK Tactics
T1016 System Network Configuration Discovery -
T1027.001 Binary Padding -
T1027.013 Encrypted/Encoded File -
T1033 System Owner/User Discovery -
T1082 System Information Discovery -
T1204.002 Malicious File -
T1547.001 Registry Run Keys / Startup Folder -
T1566.001 Spearphishing Attachment -
T1573.001 Symmetric Cryptography -
Used by Actors (1)
Metadata
ID: 175
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00