logo

Beijing went to 'EggStreme' lengths to attack Philippines military, researchers say

ID: d331da7a-a585-5ecd-9d71-e17177b60cdf

STIX ID: report--d331da7a-a585-5ecd-9d71-e17177b60cdf

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-09-11

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Bitdefender uncovered the EggStreme Framework, a sophisticated multi-stage, largely fileless in-memory malware suite deployed against a military-related organization in the Philippines. EggStreme uses multiple loaders (EggStremeFuel, EggStremeLoader, EggStremeReflectiveLoader) to launch an EggStremeAgent that injects a keylogger into explorer.exe and supports a 58-command backdoor family (including EggStremeWizard via DLL sideloading) enabling credential capture, privilege escalation, resource enumeration, arbitrary command execution, file manipulation, and data exfiltration; researchers assess the tooling and targeting are consistent with Chinese APT activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.