Netskope Threat Labs

Padodor

ATP Sandbox Adv. HeuristicsAV

Padodor (a.k.a. Berbew, Quervar, and Jubloon) is a backdoor that steals sensitive data and gives cyberattackers remote access to infected systems. It commonly arrives through web shell compromises of internet facing servers, and researchers have tracked it in campaigns that abuse legitimate web hosting for command and control.

First seen
March 2022
Last seen
September 2026
Alert Name
Backdoor.Padodor.BJ
Dropped:Backdoor.Padodor.BJ
Generic.Dacic.1.Padodor.A.37D1AA7D
Generic.Dacic.1.Padodor.A.570A0BCC
Generic.Dacic.1.Padodor.A.6238129F
Generic.Dacic.1.Padodor.A.98BA96FF
Generic.Dacic.1.Padodor.A.9D5F3A96
Generic.Dacic.1.Padodor.A.A3EE7189
Generic.Dacic.1.Padodor.A.B9AD311E
Generic.Dacic.1.Padodor.A.F3642F8C