logo

Chinese APT Actor Compromises Military Firm with Novel Fileless Malware Toolset

ID: a1f92120-f9e8-5228-a354-9e856b78c259

STIX ID: report--a1f92120-f9e8-5228-a354-9e856b78c259

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2025-09-11

Date Updated: 2026-04-22

...
...

Bitdefender reports that a Chinese state-aligned APT compromised a Philippines military contractor using a sophisticated fileless framework called "EggStreme." The multi-stage toolkit uses DLL sideloading, in-memory code injection, and living-off-the-land techniques to achieve persistent, low-profile espionage; payloads include a full-featured backdoor (EggStremeAgent) with gRPC C2 and a lightweight reverse-shell implant (EggStremeWizard). The report outlines deployment, capabilities (58 commands including keylogging and data exfiltration), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.