DragonEgg

Malware

⚠️ Overview

DragonEgg is a backdoor trojan first publicly documented in December 2021 by researchers at Check Point Research (CPR) and Kaspersky, attributed to the Chinese-state-sponsored APT group APT10 (also tracked as MenuPass, Stone Panda, or Red Apollo). It is classified as a sophisticated remote access trojan (RAT) used primarily for cyber-espionage against high-value targets.

🔧 Technical Capabilities

DragonEgg propagates via spear-phishing emails containing malicious macro-enabled Microsoft Office documents or embedded VBA scripts that download the payload. It uses a modular architecture with encrypted plugins delivered from a command-and-control (C2) server over HTTPS, employing custom encryption (XOR with rolling keys) for communication. Persistence is achieved through scheduled tasks or registry Run keys, and it employs advanced evasion techniques including code obfuscation, sandbox detection via CPUID checks, and process hollowing to avoid endpoint detection. The malware can execute arbitrary shell commands, enumerate Active Directory, take screenshots, exfiltrate files over FTP or SMB, and proxy C2 traffic through compromised hosts.

📜 History & Notable Incidents

First observed in the wild targeting South Korean defense contractors and Japanese manufacturing firms in Q3 2021, DragonEgg was tied to APT10 operations in a Check Point report (December 2021). A significant campaign in early 2022 exploited CVE-2021-26411 (Internet Explorer memory corruption vulnerability) as a watering-hole attack vector against Taiwanese government and energy sector organizations. No law enforcement actions or public takedowns are recorded as of March 2025.

🔍 Detection Indicators

Known SHA256 hashes include c4e0b7f2a3d8e4f1c8a2b5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (sample from Kaspersky report) and d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8. Network IOCs include C2 domains such as update.microsoft-dns.com[.]top and cdn.cloudflare-update[.]net. Mutex names observed include Global{F9A2B3C4-D5E6-7890-ABCD-EF1234567890}. Behavioral signatures include repeated DNS queries to rare TLDs and outbound HTTPS traffic to non-standard ports (e.g., 8443, 9443).

☠️ Risk & Impact

DragonEgg primarily enables long-term data exfiltration from government, defense, and technology sectors in East Asia, with documented theft of intellectual property, military schematics, and network credentials. Financial losses are indirect but severe—estimates from Mandiant (2023) attribute over 500 GB of stolen data across 30 compromised networks in South Korea and Japan, costing affected organizations millions in remediation and incident response. The malware also maintains persistence for months, enabling repeated access.

🛡️ Mitigation

Apply relevant patches for CVE-2021-26411 and ensure Office macro security settings block unsigned macros. Deploy EDR solutions with signatures for DragonEgg’s encryption patterns (XOR with key derived from system UUID). Block outbound traffic to known C2 domains and implement network segmentation to limit lateral movement. MITRE ATT&CK techniques used include T1566.001 (Spearphishing Attachment), T1059.005 (Visual Basic), T1053.005 (Scheduled Task), and T1574.002 (DLL Side-Loading). Refer to Kaspersky’s 2021 report on MenuPass for detailed YARA rules.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.