BeigeBurrow is a Go-compiled Windows reverse tunneling implant observed executing as agent.exe with the command line "agent.exe -server staybud.dpdns[.]org:443 -hide". It establishes a persistent, multiplexed reverse tunnel or covert TCP relay to attacker-controlled infrastructure over port 443 using HashiCorp’s yamux library. Huntress assessed with high confidence that it functions as a tunneling or proxy agent and reported it as the only observed tool in the related intrusion set that successfully achieved its intended purpose.
In the reported intrusions, BeigeBurrow appeared in post-exploitation activity following unauthorized access via a compromised FortiGate SSL VPN account and attempted use of publicly released Nightmare-Eclipse/Chaotic Eclipse tooling including BlueHammer, RedSun, and UnDefend. The surrounding activity included hands-on-keyboard reconnaissance such as whoami /priv, cmdkey /list, and net group, with BeigeBurrow used as a secondary implant to provide tunneling capability after initial access. Huntress also stated it observed BeigeBurrow in at least one other unrelated intrusion, but attribution remained unclear.
High-confidence indicators directly mentioned in the content include the C2 domain staybud.dpdns[.]org, the observed command line using port 443, and the SHA-256 hash a2b6c7a9c4490df70de3cdbfa5fc801a3e1cf6a872749259487e354de2876b7c for one observed agent.exe sample. Associated intrusion infrastructure mentioned alongside the activity includes 78.29.48[.]29, 212.232.23[.]69, and 179.43.140[.]214.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These two new disclosures are on the heels of Nightmare-Eclipse’s previously released Microsoft Defender vulnerabilities, namely BlueHammer, RedSun, and UnDefend. Reports show that these vulnerabilities are being actively exploited in the wild, however, Microsoft has only released a patch for BlueHammer.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
BeigeBurrow is a Go-compiled Windows binary that establishes a persistent, multiplexed reverse tunnel to a command-and-control (C2) server using HashiCorp's yamux library.
if needed, tunneling via a secondary implant (BeigeBurrow/agent.exe observed in the wild).
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A secondary implant used for tunneling and follow-on access after compromise.
A Go-compiled covert tunneling/backdoor utility that establishes a persistent TCP relay to attacker-controlled infrastructure over port 443 using Yamux. Unlike the privilege escalation tools, BeigeBurrow successfully connected outbound and achieved its intended purpose.
A Go-based reverse tunnel agent that maintains persistent outbound connectivity to a C2 server over TCP/443 and relays operator-directed traffic to internal hosts using yamux multiplexing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.