logo

Eagerbee backdoor deployed against Middle Eastern govt orgs, ISPs

ID: 75240cac-306f-508c-937f-17100066c287

STIX ID: report--75240cac-306f-508c-937f-17100066c287

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Eagerbee is a sophisticated persistent backdoor framework observed in targeted attacks against government organizations and ISPs in the Middle East (and cases in Japan), using a loader (tsvipsrv.dll -> ntusers0.dat -> dllloader1x64.dll) and DLL hijacking to run a plugin-based backdoor (file, process, remote access, service, network managers); Kaspersky links it to the CoughingDown group and notes past use of the Exchange ProxyLogon vulnerability (CVE-2021-26855), advising patching and use of provided IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.