A custom backdoor, SockDetour is designed to serve as a backup backdoor in case the primary one is removed. It is difficult to detect, since it operates filelessly and socketlessly on compromised #Windows servers. One of the command and control (C2) infrastructures that the threat actor used for #malware distribution for the TiltedTemple campaign hosted SockDetour along with other miscellaneous tools such as a memory dumping tool and several webshells. #microsoft #backdoor #cyber #apt #threats #informatique