logo

Philippine military company spied upon with new China-linked malware

ID: 8988d9cc-3536-51bb-ab72-e5310465b2a8

STIX ID: report--8988d9cc-3536-51bb-ab72-e5310465b2a8

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2025-09-12

Date Updated: 2026-05-01

...
...

Bitdefender disclosed EggStreme, a new fileless, multi-stage malware framework used in a year-long espionage campaign against a Philippine military company attributed to a China-linked government-backed APT. EggStremeAgent acts as a central backdoor and keylogger enabling reconnaissance, lateral movement, payload injection, and in-memory execution to evade detection; researchers observed activity from April 2024 through June 2025 and telemetry indicating attackers tested the malware against endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.