EchoDrv is a publicly available tool used to abuse a kernel read/write vulnerability in the ECHOAC anti-cheat driver as part of a bring-your-own-vulnerable-driver (BYOVD) technique. In the provided reporting, it was used by the China-linked threat actor Jewelbug (also tracked as REF7707, CL-STA-0049, and Earth Alux) during an intrusion into a Taiwanese software company in October-November 2024. In that intrusion, Jewelbug used DLL sideloading to load malware payloads, deployed ShadowPad, disabled security software with KillAV, and used EchoDrv to leverage the vulnerable ECHOAC driver for kernel-level abuse. The same activity also involved credential dumping via LSASS and Mimikatz and the use of Fast Reverse Proxy and Earthworm for tunneling and masking command/data flows. The content does not provide specific EchoDrv file indicators or additional infection vectors beyond its use as a BYOVD utility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool that exploits a kernel read/write vulnerability in the ECHOAC anti-cheat driver to facilitate BYOVD attacks.
Public tool/driver used for BYOVD-style kernel read/write abuse via a vulnerable anti-cheat driver, enabling stealthy privilege escalation and security bypass.
Tool/driver used for BYOVD-style abuse of a vulnerable anti-cheat driver to gain kernel read/write capabilities and evade defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.