Beijing went to 'EggStreme' lengths to attack Philippines military, researchers say
ID: d331da7a-a585-5ecd-9d71-e17177b60cdf
STIX ID: report--d331da7a-a585-5ecd-9d71-e17177b60cdf
Feed Name: The Register (Security)
Bitdefender uncovered the EggStreme Framework, a sophisticated multi-stage, largely fileless in-memory malware suite deployed against a military-related organization in the Philippines. EggStreme uses multiple loaders (EggStremeFuel, EggStremeLoader, EggStremeReflectiveLoader) to launch an EggStremeAgent that injects a keylogger into explorer.exe and supports a 58-command backdoor family (including EggStremeWizard via DLL sideloading) enabling credential capture, privilege escalation, resource enumeration, arbitrary command execution, file manipulation, and data exfiltration; researchers assess the tooling and targeting are consistent with Chinese APT activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
