Chinese APT Actor Compromises Military Firm with Novel Fileless Malware Toolset
ID: a1f92120-f9e8-5228-a354-9e856b78c259
STIX ID: report--a1f92120-f9e8-5228-a354-9e856b78c259
Feed Name: Infosecurity Magazine (News)
Bitdefender reports that a Chinese state-aligned APT compromised a Philippines military contractor using a sophisticated fileless framework called "EggStreme." The multi-stage toolkit uses DLL sideloading, in-memory code injection, and living-off-the-land techniques to achieve persistent, low-profile espionage; payloads include a full-featured backdoor (EggStremeAgent) with gRPC C2 and a lightweight reverse-shell implant (EggStremeWizard). The report outlines deployment, capabilities (58 commands including keylogging and data exfiltration), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
