Infosec outfit Bitdefender says it’s spotted a strain of in-memory malware that looks like the work of Chinese advanced persistent threat groups that wanted to achieve persistent access at a “military company” in the Philippines. According to an analysis released on Wednesday, someone cooked up tools called the “EggStreme Framework” that Bitdefender researchers found “operates with a clear, multi-stage flow designed to establish a resilient foothold on compromised systems.” The firm’s researchers aren’t sure how attackers infect targets with EggStreme, but spotted a server running it and found multiple components that share characteristics and therefore suggest a sophisticated development effort. The first component is called “EggStremeFuel”, which Bitdefender says deploys a tool called “EggStremeLoader” to establish a persistent service. Next comes another loader, “EggStremeReflectiveLoader”, which launches the main payload called “EggStremeAgent.” The agent monitors for new user sessions in Windows and when it finds one injects a keylogger into the active explorer.exe process. “This agent is a full-featured backdoor with a broad range of capabilities” that Bitdefender’s defenders believe has 58 commands that Bitdefender says allow attackers to launch other tools, the worst of which is a backdoor called “EggStremeWizard” that attackers use to launch “a legitimate binary that sideloads the malicious DLL.” The malware family can also enable the following nasty outcomes: Bitdef...
China went to 'EggStreme' lengths to attack Philippines
The Register
·Simon Sharwood
·Published Sep 11, 2025
·Updated
Affected Software
4 affected components
Bitdefender EggStreme Framework
Bitdefender EggStremeFuel
Bitdefender EggStremeLoader
Bitdefender EggStremeRef
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses a strain of in-memory malware known as 'EggStreme' that is believed to be linked to Chinese advanced persistent threat groups targeting a military company in the Philippines.
2
What are the security implications mentioned in the article?
The article highlights concerns over persistent access and potential espionage by state-sponsored threat actors through sophisticated malware.
3
What type of malware is identified in the article?
The malware identified in the article is an advanced form of in-memory malware designed for stealth and persistent access.
4
Which security products are associated with the malware discussed?
The affected products associated with the malware are Bitdefender's EggStreme Framework, EggStremeFuel, EggStremeLoader, and EggStremeRef.
5
Who is likely responsible for the 'EggStreme' malware attacks?
The article suggests that the attacks are likely conducted by advanced persistent threat groups from China.