China-related threat actors deployed a new fileless malware against the Philippines military

  • EggStreme is a stealthy, fileless malware framework used by a Chinese threat actor to target a Philippine military company
  • It includes six modular components, enabling reverse shell access, payload injection, keylogging, and persistent espionage
  • Attribution remains uncertain, but the attack’s objectives align with known Chinese APT tactics across APAC and beyond

A Chinese threat actor attacked a Philippine military company with a never-before-seen, fileless malware framework, researchers warned.

Earlier this week, cybersecurity outfit Bitdefender published an in-depth report about EggStreme, a “multi-stage toolset that achieves low-profile espionage by injecting malicious code directly into memory and leveraging DLL sideloading to execute payloads.”

It counts six different components: EggStremeFuel (initial loader DLL, sideloaded via a legitimate binary and establishes a reverse shell), EggStremeLoader (reads encrypted payloads and injects them into processes), EggStremeReflectiveLoader (decrypts and injects the final payload), EggStremeAgent (main backdoor implant with 58 commands), EggStremeKeylogger (grabs keystrokes and sensitive user data), and EggStremeWizard (secondary backdoor for redundancy).

Sideloading DLLs

Bitdefender tried to link the framework to known Chinese APT players, but failed to find a plausible connection, The Hacker News reported. “We put quite a lot of effort into attribution efforts, but couldn’t find anything,” Martin Zugec, technical solutions director at Bitdefender, told the publication. “However, objectives align with Chinese APTs. For this one, our attribution is based on interests/objectives.”

The objectives for this one, it seems, are cyber-espionage, reconnaissance, and long-term, low-profile persistence, something Chinese actors are known for – not just in the Philippines, but elsewhere in the region (Vietnam, Taiwan, and other neighboring countries), as well as around the world.

Salt Typhoon is perhaps the most documented Chinese APT out there, and it was recently caught in numerous telecommunications service provider companies in the US.

The EggStreme malware framework is delivered via a side-loaded DLL file. This file was activated using trusted executables, allowing it to bypass security controls. However, how the DLL file was dropped onto the victim’s device in the first place, remains unknown.

Usual methods include supply chain compromise, deploying the DLL manually (via previously obtained access), or through drive-by compromise and lateral movement.

Via The Hacker News

You might also like

Read more @ TechRadar

Latest posts

A federal jury ruled that Apple has to pay $634 million for infringing smartwatch patents

In a longstanding and complicated legal battle between Apple and Masimo, a recent ruling from a California jury may be the first step towards...

MIT researchers and beauty brand Amorepacific made a wearable patch that analyzes skin aging

Researchers at MIT have been working with the South Korean beauty company Amorepacific for the past few years to develop a wearable "electronic skin"...

I’ve been testing digital photo frames for years, and I’ve just found my favorite design – Pexar’s innovative rear-lit stunner

Pexar Starlight 15.6-inch digital photo frame: reviewThe Pexar Starlight 15.6-inch digital photo frame is an innovative photo frame built on the third-party Frameo platform....

Asus ROG NUC has a major mini PC rival – this new challenger offers fantastic specs for work and gaming, and comes from a...

Thunderobot Mix G2 delivers a 17% GPU boost over ROG NUC 2025The top configuration includes Core Ultra 9 275HX and RTX 5090 GPUNight Owl...

Here’s another chance to get the Shokz OpenRun Pro for a record-low price

Experienced runners will tell you that not all headphones and earbuds are created equal. If you regularly pound the streets, you'll care about more...

LTO tape storage is still going strong despite Elon Musk’s efforts to wipe it out – and there’s now even 40TB cartridges for the...

LTO’s 40TB cartridge pushes tape storage into the AI-driven futureAramid film gives magnetic tape the strength to expand its lifespanMagnetic tape storage remains the...

This Shark upright might not be the fanciest vacuum in town, but in terms of cleaning power I can’t fault it

Shark Stratos Upright AZ3002: two-minute reviewProduct infoThis is the vacuum on review:Shark Stratos DuoClean PowerFins Hair Pro Upright Vacuum AZ3002Shark can be erratic with...

Here are 25 of our favorite outdoorsy deals from REI’s massive Holiday Sale

You can snag the high-end Garmin Fenix 8 for a whopping $250 off right now. REI doesn’t do Black Friday, but that doesn’t mean you...

Tim Cook could step down as Apple CEO next year

Wave goodbye. According to the Financial Times, Tim Cook could step down as Apple CEO as early as next year. And the board has started...

Apple is reportedly getting ready to replace Tim Cook as early as next year

According to the Financial Times, Tim Cook may be ready to leave his position as soon as next year, and Apple's board and senior...