CoughingDown is a suspected China-nexus cyber-espionage threat actor associated with intrusions against government organizations, including targets in Russia and Belarus. The group has been linked to WebDav-O malware and has a medium-confidence association with the EAGERBEE backdoor framework based on code overlap, command-structure similarities, and overlapping command-and-control infrastructure. CoughingDown-linked activity has exploited public-facing Microsoft Exchange servers, deployed web shells, and established persistence through malicious Windows services and COM hijacking. Operators have conducted host and network reconnaissance, accessed SMB resources, used WMI for remote execution, dumped credentials, cleared event logs, collected data, and exfiltrated information through cloud-storage services. EAGERBEE-associated operations have also targeted organizations in East Asia, the Middle East, and Russia, using memory-resident modular backdoors, service-based injection, network discovery, command execution, and plugin-delivered post-compromise functionality.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possibly related actor to EAGERBEE in prior reporting.
Associated with a multi-plugin malware framework and assessed with medium confidence to be related to EAGERBEE activity. Its Core Module was executed via abuse of the legitimate MSDTC service, and overlaps with EAGERBEE included shared C2 infrastructure, code overlap, same RC4 key, and same command numbers.
Linked to the WebDav-O/Mail-O activity targeting government entities in Russia and Belarus; associated with cloud-service-based C2/exfiltration and espionage-oriented operations.
A possible China-nexus cyber-espionage actor suspected of being linked to Eagerbee deployments targeting Internet service providers and government entities in the Middle East.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.