CoughingDown is a China-linked cyber-espionage threat actor associated with intrusions against government and related organizations and linked by multiple researchers to malware and tooling including the CoughingDown Core Module, WebDav-O, and activity overlapping with the EAGERBEE malware ecosystem. The group has been connected to operations in Russia and Belarus, and possible links have also been explored in campaigns affecting Japan and other parts of Asia through shared tooling and infrastructure. Observed tradecraft includes exploitation of public-facing applications for initial access, use of malicious Windows services for execution and persistence, DLL side-loading and DLL hijacking, code injection into legitimate service processes, credential dumping, reconnaissance, lateral movement via SMB and WMI, COM hijacking, event log clearing, and data exfiltration through attacker-controlled channels and cloud services. In one documented intrusion linked to CoughingDown, attackers exploited an IIS server vulnerability, created a malicious Windows service to load a DLL through svchost, performed internal discovery and credential theft, and used remote execution and exfiltration mechanisms consistent with post-compromise espionage activity. CoughingDown has also been assessed with medium confidence to be related to EAGERBEE activity based on code overlap, shared command structures, and overlapping infrastructure. EAGERBEE is a modular backdoor and downloader framework with a plugin orchestrator and plugins for file management, process execution, service control, network enumeration, shell access, reflective loading, and RDP enablement. Related intrusions have used legitimate Windows services such as MSDTC, IKEEXT, and SessionEnv to load malicious DLLs, and have included exploitation of Microsoft Exchange via CVE-2021-26855 followed by web shell deployment. Because EAGERBEE appears to be used by multiple China-based groups, attribution of all EAGERBEE operations to CoughingDown is not warranted; however, the relationship between CoughingDown and at least part of this tooling cluster is supported by reported code and infrastructure overlap. Overall, CoughingDown is best characterized as a China-linked espionage actor that relies on modular malware, service-based persistence, stealthy in-memory execution, and conventional post-exploitation techniques to maintain access, move laterally, collect information, and exfiltrate data from targeted networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possibly related actor to EAGERBEE in prior reporting.
Associated with a multi-plugin malware framework and assessed with medium confidence to be related to EAGERBEE activity. Its Core Module was executed via abuse of the legitimate MSDTC service, and overlaps with EAGERBEE included shared C2 infrastructure, code overlap, same RC4 key, and same command numbers.
Linked to the WebDav-O/Mail-O activity targeting government entities in Russia and Belarus; associated with cloud-service-based C2/exfiltration and espionage-oriented operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.