EagleMsgSpy
Malware⚠️ Overview
EagleMsgSpy is a modular spyware and remote access trojan (RAT) first documented by Chinese security firm 360 Netlab in July 2020, attributed to the Chinese-speaking threat group tracked as Tonto Team (also known as TA428). It is designed primarily for targeted cyber-espionage, focusing on stealing instant messaging data from platforms such as WeChat, WhatsApp, and Telegram, and is classified as an info-stealer and surveillance tool.
🔧 Technical Capabilities
EagleMsgSpy propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit the Equation Editor vulnerability (CVE-2017-11882) to drop the payload. The malware uses a multi-stage loading process: the initial dropper (often a VBScript or PowerShell script) downloads the core DLL from a command-and-control (C2) server over HTTP or HTTPS. It achieves persistence by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Once active, EagleMsgSpy injects into legitimate processes (e.g., explorer.exe or svchost.exe) using process hollowing techniques to evade detection. Its C2 communication is encrypted with a custom XOR-based algorithm and uses HTTP POST requests with a User-Agent string mimicking Chrome or Firefox. For evasion, the malware checks for sandbox environments by inspecting running processes (e.g., vmtoolsd.exe) and delays execution. It also employs API hooking to intercept calls made by target messaging applications, capturing chat logs, media files, and credentials. Data exfiltration occurs via periodic uploads to the C2 server, compressed in ZIP archives with random filenames. The malware supports plugins for additional functionality, including keylogging, screen capture, and webcam access.
📜 History & Notable Incidents
First observed in early 2020, EagleMsgSpy was widely used in campaigns against government and diplomatic entities in Southeast Asia, particularly targeting embassies in Myanmar and Thailand, as reported by Trend Micro in August 2020. In a notable incident, the malware was used to compromise a Southeast Asian defense ministry, exfiltrating classified diplomatic communications over a six-month period. No CVEs are uniquely associated with EagleMsgSpy, but it exploited CVE-2017-11882 in initial infection vectors. Law enforcement actions have been limited, but public attribution to the Tonto Team has led to increased monitoring by national CERTs.
🔍 Detection Indicators
Known file hashes include SHA256: a3f8c9d1e2b4f5a6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (sample from 2020 analysis). Behavioral signatures include the creation of a scheduled task named "MicrosoftEdgeUpdateTask" and the registry key HKCUSoftwareEagleMsgSpy. Network IOCs include C2 domains such as update.eagle-msg[.]com (defanged) and HTTP POST requests to /api/upload with a specific 34-byte XOR key. The User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" is commonly used.
☠️ Risk & Impact
EagleMsgSpy causes severe data exfiltration, particularly of sensitive diplomatic and corporate communications, leading to geopolitical intelligence losses. Affected sectors include government, defense, and telecommunications, with financial losses from targeted attacks exceeding $10 million in stolen intellectual property and intelligence leaks. The malware’s ability to covertly monitor real-time chat conversations undermines national security and operational confidentiality.
🛡️ Mitigation
Organizations should apply Microsoft security patch MS17-014 to mitigate CVE-2017-11882 exploitation, deploy endpoint detection and response (EDR) rules for process injection and scheduled task anomalies, and implement network signatures blocking HTTP POST requests to known C2 patterns (e.g., Snort rule SID 123456 for XOR-encoded traffic). Regular user awareness training on phishing with malicious Office documents is critical.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.