EAGERBEE, with updated and novel components, targets the Middle East
ID: 0dddcbb6-361d-5d57-bf84-cd1bd5b311e4
STIX ID: report--0dddcbb6-361d-5d57-bf84-cd1bd5b311e4
Feed Name: Securelist by Kaspersky
This report analyzes the EAGERBEE memory-resident backdoor and associated components — a Themes-targeting service injector, a Plugin Orchestrator DLL, and multiple plugins providing file system manipulation, remote access, process and service management, and network enumeration. It documents active deployments against ISPs and government entities (Middle East and East Asia), shows use of ProxyLogon-based Exchange compromises and service DLL hijacking to load loaders and payloads, provides IoCs (hashes, IPs, domains), and assesses a medium-confidence link to the CoughingDown group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
