Malware
NESTEGG
NESTEGG is a memory-only backdoor that can proxy commands to other infected systems using a custom routing scheme.
NESTEGG is a Windows malware family operated by Lazarus Group.
Background
NESTEGG is a memory-resident backdoor capable of relaying commands to other compromised hosts via a proprietary routing scheme. It handles commands to upload and download files, enumerate and delete files, enumerate and kill processes, and spawn new processes. It also adds Windows Firewall rules so the backdoor can bind to a chosen port and accept inbound connections.
Source: Malpedia (Fraunhofer FKIE).