Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSockDetour was a custom Windows backdoor designed to remain as a backup if an attacker’s primary backdoor was detected and removed. In the samples analyzed by Palo Alto Networks’ Unit 42, it ran in memory inside a legitimate service process and reused that process’s listening network socket for command-and-control (C2), rather than opening a new port. Unit 42 reported that at least four U.S.-based defense contractors were targeted and at least one was compromised.
What is the SockDetour backdoor?
SockDetour is a custom backdoor for Windows that Unit 42 described in 2022 as a persistence mechanism intended to provide a fallback foothold. As the report put it, “A custom backdoor, SockDetour is designed to serve as a backup backdoor in case the primary one is removed.” That purpose matters: removing a known initial backdoor would not, by itself, prove that an affected server was free of attacker access.
In the analyzed samples, SockDetour was “fileless” in the sense that operators injected its shellcode into a running process instead of relying on a conventional backdoor executable installed on disk. It was “socketless” in the sense that it did not establish C2 by opening its own listening port; it intercepted traffic through a socket the host process already used. These terms describe this malware’s observed design, not a universal behavior of fileless malware. Unit 42’s technical report provides the technical analysis and indicators.
How did SockDetour target U.S. defense contractors?
Unit 42 placed the activity in the TiltedTemple campaign, which it was tracking in connection with exploitation of ManageEngine ADSelfService Plus (CVE-2021-40539) and ServiceDesk Plus (CVE-2021-44077). The report described evidence that at least four U.S.-based defense contractors were targeted and at least one was compromised. Those are minimum counts in Unit 42’s observations and analysis, not a government-confirmed total or a measure of all victims.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →For one contractor, Unit 42 found evidence that SockDetour was delivered from an external FTP server to an internet-facing Windows server on July 27, 2021. The FTP server was hosted on a compromised QNAP small-office/home-office NAS appliance. Unit 42 assessed that the threat actor likely exploited vulnerabilities including CVE-2021-28799 to compromise the NAS; the report framed this as a likely explanation, not a confirmed exploit chain.
What is known about when it appeared?
July 27, 2021 is the report’s specific delivery observation. Unit 42 said SockDetour may have been in the wild since July 2019, but that is a possible earliest-use estimate, not an established first-use date. The report did not provide a population-level prevalence statistic or an independently measured infection rate.
Who was behind the attacks?
The original SockDetour report associated the activity with TiltedTemple but said Unit 42 could not determine whether one or multiple threat actors were involved. A later Unit 42 brief said tactics seen during another event aligned with DEV-0391, then known as Volt Typhoon; that later context does not establish that the original SockDetour activity was definitively conducted by Volt Typhoon. The later Unit 42 brief describes that separate attribution context.
How did SockDetour work?
Unit 42’s analysis described a sequence that concealed both the backdoor’s code and its network traffic within normal Windows service activity:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Prepare shellcode. Operators used a PowerSploit memory injector and converted SockDetour into shellcode with the Donut framework.
- Inject into a selected process. The injector placed the shellcode in a manually selected process on a compromised Windows server. Samples analyzed by Unit 42 contained hardcoded target process IDs.
- Hook the service’s network handling. SockDetour used Microsoft Detours to hook Winsock’s
accept()function in a service process that already had a listening TCP port. - Recognize covert C2 traffic. The backdoor inspected incoming data for a distinctive pattern, including a TLS-like record prefix without a normal TLS handshake. Matching traffic was authenticated and then used for encrypted C2.
- Keep ordinary traffic working. Connections that did not match the C2 pattern were passed back to the original service, allowing normal service traffic to continue.
This approach avoided a new listening port and an ordinary outbound connection to establish C2. Reusing a legitimate service’s socket could make the backdoor less obvious to checks focused only on unfamiliar ports or outbound connections, but the report’s description is specific to the analyzed SockDetour samples.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should defenders do?
Unit 42’s report recommends keeping Windows servers up to date, using its YARA rule to look for SockDetour in memory, and investigating systems when compromise is suspected. Because the backdoor was designed as a backup, responders should not treat removal of a known primary backdoor as proof that persistence has been eliminated.
Rank #4
- Review the primary report’s indicators. Use the report’s full indicator set and context rather than relying on a single hash. It includes a SockDetour PE hash and hashes associated with memory injectors.
- Scan memory with the report’s YARA rule. Memory-focused detection is relevant to the behavior Unit 42 described; a disk-only check may not reveal an injected backdoor.
- Investigate suspected systems. Assess the affected server and related activity for other persistence or signs of compromise, following your incident-response procedures.
- Patch Windows servers. Unit 42 specifically advised administrators to keep servers up to date. The report does not establish a single vulnerability in Windows as SockDetour’s delivery route.
Unit 42 also described detections and tracking in Palo Alto Networks products including Cortex XDR, WildFire, and AutoFocus. Those are vendor-stated capabilities in the report, not independent comparative test results. The report’s technical details, YARA rule, and current indicator list are available at Unit 42’s SockDetour report.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors

