Description
Padodor (a.k.a. Berbew, Quervar, and Jubloon) is a backdoor that steals sensitive data and gives cyberattackers remote access to infected systems. It commonly arrives through web shell compromises of internet facing servers, and researchers have tracked it in campaigns that abuse legitimate web hosting for command and control.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| Backdoor.Padodor.BJ |
| Dropped:Backdoor.Padodor.BJ |
| Generic.Dacic.1.Padodor.A.37D1AA7D |
| Generic.Dacic.1.Padodor.A.570A0BCC |
| Generic.Dacic.1.Padodor.A.6238129F |
| Generic.Dacic.1.Padodor.A.98BA96FF |
| Generic.Dacic.1.Padodor.A.9D5F3A96 |
| Generic.Dacic.1.Padodor.A.A3EE7189 |
| Generic.Dacic.1.Padodor.A.B9AD311E |
| Generic.Dacic.1.Padodor.A.F3642F8C |