WinEggDrop is an open-source Windows port scanner used for network service discovery and host reconnaissance. In the provided content, it is specifically associated with Agrius, which used WinEggDrop to perform detailed scans of hosts of interest inside victim networks during post-compromise discovery and lateral movement preparation. The content also notes that ESET observed a WinEggDrop sample signed with the same stolen code-signing certificate used in a Winnti Group PipeMon campaign, alongside other attacker tools such as HTran, Netcat, and Mimikatz; however, the content does not state that WinEggDrop itself is exclusive to or developed by that group. High-confidence behavior described here is limited to detailed port scanning of victim hosts for internal reconnaissance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.
Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Port-scanning tool mentioned as an additional utility potentially used by the operators and signed with the same stolen certificate.
Open-source port scanner used to perform detailed scans of hosts of interest in victim networks.
Open-source network scanner used for discovery and reconnaissance of hosts/services inside victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.