EchoGather

Malware

⚠️ Overview

EchoGather is a passive remote access trojan (RAT) discovered by cybersecurity firm Trend Micro in July 2022, attributed to the Chinese state-sponsored threat group tracked as Earth Baku (also associated with APT41). It functions as a backdoor for credential theft, system reconnaissance, and data exfiltration, primarily targeting government entities, telecommunications firms, and research institutions in Southeast Asia and the Middle East. The malware operates as a second-stage payload delivered through spear-phishing attachments or exploited public-facing applications (MITRE ATT&CK ID T1193).

🔧 Technical Capabilities

EchoGather employs DLL side-loading (MITRE ATT&CK ID T1055) via a legitimate signed executable to load its malicious payload, bypassing application control mechanisms. It collects system information (OS version, installed software, running processes) and harvests credentials by hooking Windows APIs (MITRE ATT&CK ID T1003) and dumping LSASS memory. The malware communicates over HTTPS to command-and-control (C2) servers using a custom encryption scheme based on AES-128-CBC with a static key embedded in its binary. It supports file upload/download, keylogging, screen capture, and remote shell execution. Persistence is achieved via scheduled tasks or registry Run keys (MITRE ATT&CK ID T1053.005/T1547.001). Evasion techniques include sleeping before beaconing, checking for sandbox artifacts (e.g., disk size, MAC addresses of known VMWare adapters), and terminating if a debugger is detected.

📜 History & Notable Incidents

EchoGather was first observed in a campaign targeting a Southeast Asian telecommunications ministry in August 2022, as reported by Trend Micro in their December 2022 threat assessment. In March 2023, a variant was used in a supply-chain attack against a Middle Eastern logistics provider, exploiting an unpatched vulnerability in a third-party web application (CVE-2022-40634, a path traversal flaw in a content management system). No law enforcement actions have been publicly documented. The malware’s C2 infrastructure has been linked to IP addresses previously associated with Earth Baku’s operations.

🔍 Detection Indicators

Known file hashes include SHA256 d3a2c9f1e4b8a7c0d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8 and MD5 e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (from Trend Micro's IoC list). Network indicators include HTTP POST requests to /api/log with a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36. Persistence mutex names observed include EchoGatherMutex_v2 and GlobalSessMgr_Mutex. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value svchosts.

☠️ Risk & Impact

EchoGather enables full remote control over compromised systems, leading to large-scale data exfiltration and prolonged lateral movement within victim networks. Impacted sectors include government, telecommunications, and logistics, with incident response reports indicating the theft of classified diplomatic communications and employee credentials used for subsequent wire fraud. Financial losses from associated data breaches have been estimated in the tens of millions of dollars due to remediation costs and regulatory fines.

🛡️ Mitigation

Defenders should enable application control policies to block unsigned DLL loads and deploy endpoint detection and response (EDR) rules that flag HTTL connections with EchoGather’s User-Agent pattern. Regularly apply security patches for CVE-2022-40634 and other web application vulnerabilities. Network segmentation and least-privilege access controls reduce lateral movement risk, while email filtering and user awareness training mitigate initial phishing vectors.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.