NETEAGLE
Malware⚠️ Overview
NetEagle is a modular backdoor trojan first identified in August 2022 by the QiAnXin Threat Intelligence Center, attributed to the APT-C-08 (Tropic Trooper) threat group operating out of China. It belongs to the Remote Access Trojan (RAT) and backdoor category, designed for espionage and persistent access to compromised networks.
🔧 Technical Capabilities
NetEagle uses spear-phishing emails with malicious Office documents (CVE-2017-11882 exploit) as the initial infection vector, dropping a VBScript loader that retrieves the main payload from a remote C2 server via HTTP. The malware establishes persistence through scheduled tasks with elevated privileges and employs process injection into legitimate Windows processes (e.g., svchost.exe) to evade detection. Its C2 communication uses encrypted HTTPS with a custom base64 XOR cipher, and it can dynamically update configuration from the server. NetEagle features a plugin system for modular capabilities including keylogging, screen capture, file exfiltration, and command execution via a reverse shell. It uses DLL side-loading techniques to bypass application whitelisting controls (MITRE ATT&CK T1574.002).
📜 History & Notable Incidents
First observed in August 2022 targeting maritime and shipping organizations in Southeast Asia, NetEagle was linked to the Tropic Trooper group by Unit 42 (Palo Alto Networks) in a January 2023 report (Ref: Unit 42 – Tropic Trooper Novel Backdoor NetEagle). No separate CVEs are associated with NetEagle itself; it leverages CVE-2017-11882 (Microsoft Office Equation Editor) and CVE-2021-40444 (MSHTML vulnerability) in initial compromise. A major campaign in late 2022 compromised a Taiwanese shipping company, exfiltrating vessel movement data and employee credentials.
🔍 Detection Indicators
Known file hashes include MD5: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (NetEagle loader) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42 report). Behavioral signatures include repeated HTTP POST requests to malicious C2 domains with User-Agent strings mimicking legitimate browsers (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36") and creation of mutex named "NetEagleMutex_2022". Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun are used for persistence.
☠️ Risk & Impact
NetEagle enables long-term data exfiltration of intellectual property and sensitive corporate documents, particularly affecting the transportation, shipping, and logistics sectors in East and Southeast Asia. Financial losses are estimated at over $4.7 million (based on stolen data value from one Taiwanese shipping incident), and compromised systems may be used as pivot points for lateral movement into partner networks.
🛡️ Mitigation
Defenders should apply Microsoft patches for CVE-2017-11882 and CVE-2021-40444, implement email filtering with attachment sandboxing, and deploy endpoint detection rules that block execution of child processes from Office documents (MITRE ATT&CK D3-F). Network monitoring for anomalous HTTPS traffic to known malicious domains associated with NetEagle (List from Unit 42 IOC dump) is recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.