Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:43:53 UTC Home > List all groups > List all tools > List all groups using tool Merdoor Tool: Merdoor Names Merdoor Category Malware Type Backdoor, Keylogger Description (Symantec) Merdoor is a fully-featured backdoor that appears to have been in existence since 2018. The backdoor contains the following functionality: • Installing itself as a service • Keylogging • A variety of methods to communicate with its command-and-control (C&C) server (HTTP, HTTPS, DNS, UDP, TCP) • Ability to listen on a local port for commands Information Malpedia Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool Merdoor Changed Name Country Observed APT groups   Lancefly [Unknown] 2018   1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e3a23b2e-3e2f-462f-9d4d-f3b13f8995a9 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e3a23b2e-3e2f-462f-9d4d-f3b13f8995a9 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e3a23b2e-3e2f-462f-9d4d-f3b13f8995a9 Page 2 of 2 APT groups Lancefly [Unknown] 2018 1 group listed (1 APT, 0 other, 0 unknown) Page 1 of 2