VARGEIT is a custom backdoor associated with the China-aligned espionage cluster tracked as Jewelbug, Ink Dragon, Earth Alux, CL-STA-0049, and REF7707. It has been described as an earlier variant within the same malware family later tracked as FINALDRAFT or Squidoor. The malware has been used in multi-stage intrusions following exploitation of internet-exposed IIS and SharePoint environments, where operators deploy web shells and then deliver VARGEIT as a follow-on payload.
VARGEIT has been used to establish command and control and support broader post-compromise activity including discovery, lateral movement, defense evasion, persistence, credential theft, and data exfiltration. Reporting links the broader toolset around VARGEIT to process injection, DLL side-loading, abuse of legitimate Windows binaries, and credential access from browsers and LSASS during Earth Alux and Ink Dragon operations. The malware has been observed in campaigns targeting government, telecommunications, technology, logistics, manufacturing, IT services, retail, and military-related communications environments across Asia-Pacific, Latin America, Europe, the Middle East, Africa, and South Asia.
The malware is part of a mature espionage ecosystem that emphasizes stealth, resilient command infrastructure, and long-term access. Associated operations have used covert channels such as Microsoft Graph and Outlook APIs, DNS tunneling, and ICMP tunneling, and have paired VARGEIT with other tooling including web shells, ShadowPad-related components, COBEACON, and additional custom loaders and persistence mechanisms. High-confidence reporting also indicates that the malware family evolved over time, with newer FINALDRAFT variants extending functionality and stealth while preserving the same core family lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers found the actor typically gained access through vulnerable IIS and SharePoint servers before deploying web shells and a sophisticated backdoor tracked as VARGEIT, Squidoor or FinalDraft.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated backdoor used after initial access via vulnerable IIS and SharePoint servers, supporting covert C2 via Microsoft Graph/Outlook APIs, DNS tunnelling, and ICMP tunnelling.
Malware used in a multi-stage intrusion chain attributed to the China-linked actor Earth Alux; used as part of cyber intrusions against multiple sectors in APAC and LATAM.
An earlier-stage variant of the same malware family as FINALDRAFT, used as an additional payload to support C2 and post-compromise activity (e.g., discovery, lateral movement, defense evasion, and data exfiltration).
Malware delivered by Earth Alux and related clusters, specific functionality not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.