Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CoughingDown

Also known as: TA428, tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Colourful Panda, BRONZE DUDLEY, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

CoughingDown is an underground malicious actor that systematically acquires and rents cloud infrastructure, email accounts, and other public services as low‑cost footholds for its campaigns. After gaining initial access—often through compromised third‑party web, email or cloud credentials—it creates local or domain user accounts to maintain persistence while exploiting service binaries (e.g., MSDTC, IKEEXT, SessionEnv) to deploy DLLs such as oci.dll. The group’s operational arsenal includes the EAGERBEE backdoor, which is delivered via native Windows utility chains and exploits permission abuse on services like rundll32.exe and sc.exe. It also employs polymorphic/mutating code, software packing, command obfuscation, and base64‑encoded payloads to evade signature‑based detection. CoughingDown’s tactics extend beyond malware delivery: it routinely exfiltrates data over public cloud or web storage services, hijacks browser sessions, spoofs User‑Agent headers for traffic blending, and launches endpoint denial‑of‑service attacks by exhausting resources or triggering application crashes. These activities are orchestrated through both custom command‑and‑control channels over common protocols (HTTP/HTTPS) and leveraged remote‑execution utilities such as PowerShell, mshta, and BITS jobs. The actor’s choice of cloud‑abusive infrastructure and broad sector coverage signals an intent to monetize stolen data or leverage disruption for ransom while minimizing traceability by using widely available consumer services.

Goals & Targeting

Targeted Sectors

Government
Media
Defense
Financial services
Healthcare
Manufacturing
Telecommunications
Critical infrastructure
Education
Information technology

Targeted Countries / Regions

CN
SY

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

CoughingDown (alias TA428) is a financially motivated threat group that leverages cloud and third‑party services for initial access, persistence, and command & control. The actor deploys the polymorphic EAGERBEE backdoor, hijacks legitimate Windows services, and performs network denial‑of‑service attacks to disrupt targeted organizations. Its operations span across high‑value sectors in China and Syria, indicating a blend of espionage and extortion objectives.

Goals & Targeting

CoughingDown’s strategic focus is to acquire high‑value information from governments, defense contractors, media outlets, financial institutions, and critical infrastructure operators—primarily within Chinese and Syrian jurisdictions—and convert it into monetary gain or leverage. By exploiting ubiquitous cloud platforms and social engineering vectors, the actor reduces acquisition costs while increasing operational stealth. The mix of exfiltration, data theft, and disruptive attacks suggests a dual motive: immediate monetization through ransomware or data‑leasing channels, augmented by threat‑oriented Denial‑of‑Service campaigns aimed at extracting concessions or causing reputational damage.

Enhanced Description

Key Capabilities

  • Purchasing/retrieving cloud infrastructure for C2
  • Compromising third‑party web/email/cloud accounts to gain access
  • Creating local/domain accounts for persistence
  • Using web services for command & control communications
  • Exfiltrating data via web protocols and cloud storage
  • Deploying polymorphic backdoor EAGERBEE
  • Endpoint Denial‑of‑Service attacks through resource exhaustion or crash exploitation
  • Hijacking Windows services by abusing binary permissions
  • Implanting malicious code in cloud/container images
  • Spoofing browser/system attributes (e.g., User‑Agent) to blend traffic
  • Generating polymorphic/mutating code
  • Packing and obfuscation of software
  • Command obfuscation
  • Encryption/encoding of payloads
  • Port scanning, vulnerability scanning, wordlist scanning
  • Account creation on email providers for phishing or exfiltration

MITRE ATT&CK Tactics

Credential Access
Execution
Persistence
Privilege Escalation
Discovery
Lateral Movement
Command And Control
Defense Evasion
Exfiltration
Impact

ATT&CK Techniques

T1037
T1557
T1583
T1613
T1123
T1543
T1547
T1119
T1115
T1071.001
T1555
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1136.001
T1526

Software / Tooling

EAGERBEE
Poison Ivy
Mirage Kitten
CotX RAT
GhostEmperor
mshta
BITS Jobs
PowerShell
GitHub (custom scripts)
Msiexec

Campaigns & Victims

CoughingDown has conducted multiple operations across a broad spectrum of sectors, most notably an attack on the code‑hosting service Codecov that leveraged supply‑chain techniques. The actor frequently abuses legitimate Windows services—especially MSDTC and SessionEnv—to load malicious DLLs like oci.dll and establish persistence. Its use of cloud platforms for both command & control and data exfiltration illustrates a low‑cost, high‑impact model, while repeated DoS attacks against DNS, web, and email services suggest extortionary motives or pressure campaigns. Though the timeline is unclear, patterns indicate sustained activity with opportunistic adaptation to newer hosting services and evasive techniques such as polymorphic code.

IOC Patterns

  • Compromised email account usage
  • Compromised cloud storage account for exfiltration
  • Web service based command & control traffic
  • Unauthorized local/domain account creation on compromised hosts
  • DNS/web/email denial‑of‑service attempts via malicious domains
  • Exploitation of application/OS vulnerabilities to cause crashes
  • Account provisioning on email providers for phishing campaigns
  • Cloud storage utilization for tool upload or data staging
  • Spoofed HTTP User‑Agent headers disguising malware traffic
  • Polymorphic/mutating code signatures detected in binaries
  • Software packing and obfuscation patterns
  • Base64‑encoded or otherwise encrypted payloads
  • High‑volume network activity indicative of DoS or Lateral movement
  • Port, service, and vulnerability scanning behavior

Recommended Actions

  • Monitor outbound connections to commercial web services (e.g., cloud storage, CDN) for suspicious C2 traffic
  • Enforce least privilege principles; detect & block unauthorized creation of local/domain accounts on endpoints
  • Implement MFA across all email and cloud environments to limit account compromise""
  • Deploy network segmentation and deep packet inspection to identify data exfiltration over web protocols
  • Integrate host‑based IDS/EDR rules for EAGERBEE backdoor signatures and known DLL implants
  • Apply rate limiting and hardening on critical services to mitigate DoS potential","Regularly patch operating systems and software to close vulnerabilities used by the actor for exploitation","Restrict write permissions on binary service executables; monitor file integrity of rundll32.exe, sc.exe, svchost.exe","Detect anomalous account creation in email/cloud providers; alert security teams promptly","Implement User‑Agent anomaly detection to flag spoofed browser headers","Adopt container image signing and scanning before deployment; verify image integrity","Deploy behavioral analytics capable of spotting polymorphic malware behaviors (e.g., DLL injection, privilege escalation attempts)
  • Use signature‑less detection for heavily obfuscated code
  • Leverage DDoS protection services or rate limiting on critical internet-facing assets

Suggested Tags

CoughingDown
EAGERBEE
Adversary-Infrastructure
Cloud-Abuse
Phishing
Account-Compromise
Web-Service-C2
Data-Exfiltration
Denial-of-Services (Distributed & Endpoint)
Service-Hijack
Account-Creation
Cloud-Persistence
Browser-Spoofing
Vulnerability-Exploitation
Polymorphic-Malware
Obfuscation-Techniques
Network-DoS
Port-Scanning
Reconnaissance
China
Syria
Financial-Gain
High-Value-Targets
Critical-Infrastructure

Confidence Assessment

The analysis is based on multiple independent source fragments that associate EAGERBEE with the CoughingDown actor and provide evidence of specific TTPs (service hijacking, cloud abuse, polymorphic backdoor). While this correlation gives moderate to high confidence in the group’s operational profile, gaps remain regarding precise attribution details, full campaign timelines, and the extent of infrastructure used. Further evidence such as IP blocks, threat‑share records, or forensic artifacts would strengthen confidence.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: PowerShell
  3. www.kaspersky.com — Cited by web research for: phishing
  4. https://www.cisa.gov — Cited by AI analysis.
  5. https://www.kaspersky.com — Cited by AI analysis.

Intel Summary

42

Techniques

45

Tools

0

Campaigns

65

IOCs

0

Observed Data

13

Tactics

Tags

Backdoor / C2
APT
supply-chain attack
persistence
backdoor
infrastructure abuse
DLL injection
CoughingDown
EAGERBEE
Adversary-Infrastructure
Cloud-Abuse
Phishing
Account-Compromise
Web-Service-C2
Data-Exfiltration
Denial-of-Services (Distributed & Endpoint)
Service-Hijack
Account-Creation
Cloud-Persistence
Browser-Spoofing
Vulnerability-Exploitation
Polymorphic-Malware
Obfuscation-Techniques
Network-DoS
Port-Scanning
Reconnaissance
China
Syria
Financial-Gain
High-Value-Targets
Critical-Infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.