CoughingDown is a threat actor deploying the EAGERBEE backdoor through supply-chain attacks using Trojanized packages.
Analyst brief
CoughingDown is a threat actor linked to campaigns deploying the EAGERBEE backdoor, known for supply-chain attacks using Trojanized packages. The group leverages service manipulation and privilege escalation, abusing legitimate services like MSDTC, IKEEXT, and SessionEnv to load malicious DLLs such as oci.dll. Defenders should monitor for unusual service creation, C2 domain overlaps, and suspicious DLL injection into legitimate processes.
CoughingDown
unknown
CoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation and privilege escalation techniques. The group has been linked to malware infrastructure that abuses legitimate services like MSDTC, IKEEXT, and SessionEnv to load malicious DLLs, including oci.dll. Analysis of supply-chain attacks, particularly involving Trojanized packages, has revealed similarities between CoughingDown malware and post-compromise tools used in these incidents. Evidence such as consistent service creation and C2 domain overlap further supports the connection between EAGERBEE and CoughingDown.