EagerBee Backdoor Takes Flight Against Mideast ISPs, Government Targets
ID: 2279296c-1892-5a7e-a684-b77d0a07c422
STIX ID: report--2279296c-1892-5a7e-a684-b77d0a07c422
Feed Name: Dark Reading
Date Published: 2025-01-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Kaspersky researchers have identified a strengthened variant of the EagerBee backdoor being used in targeted attacks against ISPs and government organizations in the Middle East. The malware is memory-resident, hides by injecting into legitimate processes (e.g., explorer.exe), features a novel service injector and a modular plug-in orchestrator enabling file management, process control, remote access, and service management, and collects detailed system and victim metadata. Kaspersky links the activity with medium confidence to the China-aligned CoughingDown actor, notes the initial access vector remains undetermined for these incidents, and recommends defenders patch known Exchange ProxyLogon vulnerabilities and increase vigilance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
