How to detect and remove attacker-installed backdoors from corporate networks

Many Australian enterprises have learned the hard way that a breach rarely ends with the initial intrusion. The 2022 Optus incident, the Medibank data exposure, and the prolonged Toll Group ransomware event all demonstrated how attackers often leave a secondary foothold — a backdoor — waiting quietly in case they need to return. For security teams in Sydney, Melbourne, Brisbane and beyond, finding and dismantling these implants has become a recurring operational task rather than a rare emergency.

This guide walks through how to detect and remove backdoors installed by attackers, from the entry vectors most commonly seen in Australian organisations, through detection techniques that hold up under pressure, to safe removal, regulatory coordination and post-incident recovery. The aim is to give defenders a workable sequence of actions that holds up even when an adversary is still active inside the environment.

Common backdoor entry points in Australian organisations

Attackers rarely plant a backdoor without first gaining some form of access. Phishing remains the most common starting point, and campaigns targeting Australian organisations often impersonate myGov, the Australian Taxation Office, or major retailers during the end-of-financial-year rush. A single click on a malicious attachment or a credential-harvesting page is frequently enough to establish an initial foothold that later evolves into a persistent implant.

Once inside, adversaries look for ways to return. Common persistence mechanisms include web shells dropped on internet-facing IIS or Apache servers, scheduled tasks and services on Windows endpoints, malicious cron jobs on Linux systems, and tampering with cloud identity providers such as Microsoft Entra ID or Okta. Email is a particularly fertile channel because forwarded mail rules, auto-forwarders, and compromised OAuth tokens allow attackers to monitor communications without raising obvious alarms — a pattern that shows up clearly when teams review DMARC forwarded email signals alongside mail flow logs.

Supply-chain access is another growing concern. Several Australian managed service providers have been compromised in recent years, and attackers have ridden those channels directly into the networks of accounting practices, mining contractors and regional councils in Western Australia and Queensland. Anywhere attackers gain privileged access, a persistent backdoor is a likely follow-up, and that is why initial access handling has become a serious security control requirement that sits alongside patching and identity hygiene.

Warning signs that a backdoor is hiding in plain sight

Backdoors are designed to be quiet, but they almost always leave fingerprints. Unexplained outbound network traffic to unfamiliar IP ranges, especially over non-standard ports or TLS to a recently registered domain, is one of the strongest indicators. Australian defenders should treat any sudden growth in outbound DNS requests, anomalous SMTP relay activity, or traffic to known bulletproof hosting providers as a triage trigger.

On the host itself, look for scheduled tasks that reference executables from temporary directories, services running under unexpected user contexts, and new local accounts created outside the normal onboarding window. Registry run keys, autostart extensibility points, and WMI event subscriptions are common persistence favourites. In Linux, suspicious entries in /etc/crontab, ~/.ssh/authorised_keys, or the docker group deserve close attention because user accounts and legitimate data may be at risk if those paths are compromised.

Cloud and identity layers deserve the same scrutiny. New OAuth applications granted high-privilege Graph permissions in Microsoft 365, conditional access policies that have been weakened overnight, or unfamiliar service principals in Azure often signal that an attacker is building an alternative route back in. Mailbox-level forwarders created without a matching ticket in the change-management system are another classic Australian tell, particularly in organisations that have been hit by business email compromise during the EOFY invoicing push.

Detection methods that work in the real world

Endpoint detection and response platforms remain the workhorse for catching in-memory implants, fileless malware, and living-off-the-land binaries abused for persistence. Tuning EDR to flag suspicious uses of rundll32, msbuild, regsvr32, and other signed Microsoft tools can surface activity that traditional antivirus quietly misses. Pair EDR signals with Sysmon or a Linux equivalent so that process creation events are captured with full command-line fidelity for later analysis.

Network detection is just as important. JA3/JA3S fingerprinting, DNS logging, and NetFlow analysis all help to identify beaconing behaviour that would otherwise look like ordinary HTTPS traffic. For organisations that operate across multiple Australian sites, aggregating these signals into a single SIEM view — often delivered through a Sydney- or Perth-based managed detection and response partner — shortens the time between implant execution and analyst action.

Threat hunting should run continuously rather than as a one-off. Hypotheses built around MITRE ATT&CK techniques such as T1059 (Command and Scripting Interpreter), T1543 (Create or Modify System Process) and T1078 (Valid Accounts) give hunters a repeatable structure. Memory scans with tools like Volatility, periodic sweeps of IIS logs for encoded web shell fragments, and reviews of authentication logs for impossible travel from Brisbane or Adelaide when no one is travelling are practical hunts that catch what automated tools miss.

The table below compares the persistence techniques most often observed in Australian incidents, where they hide, and the indicators that most reliably surface them.

Persistence technique Typical hiding place Most reliable detection signal
Web shell IIS or Apache web roots, upload folders, encoded .aspx or .php files New or modified scripts outside of deployment windows
Windows service or scheduled task Service Control Manager, Task Scheduler, WMI subscriptions Service binaries running from %TEMP% or user profile paths
Linux cron or systemd timer /etc/crontab, /etc/cron.d, systemd unit files New entries without matching change tickets or peer reviews
Cloud identity abuse OAuth grants, service principals, conditional access policies New high-privilege apps, weakened MFA, federation changes
Mailbox forwarder Inbox rules, SMTP forwarding, OAuth IMAP External auto-forwarders created without a corresponding ticket

Safely removing a backdoor without tipping off the adversary

Removal is where many incident responses go wrong. Pulling the implant immediately can alert the attacker and push them toward faster, more destructive actions such as ransomware staging or data destruction. The safer sequence is to first contain the affected segment — segment the network, block the relevant outbound destinations at the firewall, and revoke the tokens or credentials the backdoor depends on — while preserving forensic state.

Once the implant is contained, capture volatile evidence: running processes, network connections, loaded modules, and memory if practical. Image the host before reimaging so the team can build a timeline of dwell and lateral movement across the Australian estate. Only then should the implant itself be removed, ideally by rebuilding the system from a trusted baseline. Simply deleting a file or removing a scheduled task rarely erases the entire foothold, because the attacker may have planted multiple redundant persistence mechanisms.

For cloud and identity compromises, the playbook is similar but the tooling differs. Rotate any credentials that may have been exposed, revoke OAuth refresh tokens, rebuild service principals, and review federation trust settings. In Microsoft Entra, audit conditional access and MFA registration changes for the prior ninety days, and close out mailbox rules that may have been auto-forwarding mail externally. Where business email compromise is suspected, treat every inbox rule and OAuth grant as suspicious until reviewed.

Coordinating response with Australian regulators and partners

Australian organisations have specific obligations once a breach is confirmed. The Notifiable Data Breaches scheme under the Privacy Act 1988 requires entities covered by the Act to notify the Office of the Australian Information Commissioner and affected individuals when serious harm is likely. The Australian Cyber Security Centre's ReportCyber service is the primary channel for engaging law enforcement and receiving technical remediation support. Sector-specific regulators — APRA for banks, ASIC for financial services, and the Department of Home Affairs for critical infrastructure — have their own notification expectations that must be met in parallel.

Practical coordination looks like this: the incident response lead engages CARM or a similarly integrated remediation platform to orchestrate containment, eradication and recovery across multiple vendor technologies. Legal and privacy teams assess notifiable data breach obligations while the technical team is still working. Communications prepares holding statements that can be released quickly if media enquiry volume increases. The board receives a single-page summary that covers impact, response status, regulatory notifications and estimated recovery time.

Many Australian organisations also lean on industry partners during an active incident. The Financial Services Information Sharing and Analysis Center, the Health ISAC for healthcare providers, and the Australian Retailers Association all run member channels that share threat intelligence. These communities are particularly valuable in the first hours of an incident, when fresh indicators and remediation advice are most needed and standard vendor support lines are stretched.

Hardening priorities to schedule this quarter

The next concrete step is to book a thirty-minute scoping call with the CARM Security team to map the existing detection and response stack against the workflow above. That single session will surface the largest coverage gaps in the environment and put a written remediation plan in front of the executive team within the same week.