NETEAGLE

S0034

Malware.View on attack.mitre.org

About this malware

NETEAGLE is a backdoor developed by APT30 with compile dates as early as 2008. It has two main variants known as “Scout” and “Norton.”

Techniques used11

Procedure examples11

TechniqueProcedure example
T1008
Fallback Channels

NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000.

T1041
Exfiltration Over C2 Channel

NETEAGLE is capable of reading files over the C2 channel.

T1057
Process Discovery

NETEAGLE can send process listings over the C2 channel.

T1059.003
Windows Command Shell

NETEAGLE allows adversaries to execute shell commands on the infected host.

T1071
Application Layer Protocol

Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519.

T1071.001
Web Protocols

NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request. NETEAGLE will also use HTTP to download resources that contain an IP address and Port Number pair to connect to for further C2.

T1083
File and Directory Discovery

NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information.

T1095
Non-Application Layer Protocol

If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs.

T1547.001
Registry Run Keys / Startup Folder

The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1568
Dynamic Resolution

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

T1573.001
Symmetric Cryptography

NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle."

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT30 Open source
    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.