• News/
  • https://www.theregister.com/2025/09/11/eggstreme_malware_china_philippines/

China went to 'EggStreme' lengths to attack Philippines

The Register
·
Simon Sharwood
·
Published Sep 11, 2025
·
Updated

Infosec outfit Bitdefender says it’s spotted a strain of in-memory malware that looks like the work of Chinese advanced persistent threat groups that wanted to achieve persistent access at a “military company” in the Philippines. According to an analysis released on Wednesday, someone cooked up tools called the “EggStreme Framework” that Bitdefender researchers found “operates with a clear, multi-stage flow designed to establish a resilient foothold on compromised systems.” The firm’s researchers aren’t sure how attackers infect targets with EggStreme, but spotted a server running it and found multiple components that share characteristics and therefore suggest a sophisticated development effort. The first component is called “EggStremeFuel”, which Bitdefender says deploys a tool called “EggStremeLoader” to establish a persistent service. Next comes another loader, “EggStremeReflectiveLoader”, which launches the main payload called “EggStremeAgent.” The agent monitors for new user sessions in Windows and when it finds one injects a keylogger into the active explorer.exe process. “This agent is a full-featured backdoor with a broad range of capabilities” that Bitdefender’s defenders believe has 58 commands that Bitdefender says allow attackers to launch other tools, the worst of which is a backdoor called “EggStremeWizard” that attackers use to launch “a legitimate binary that sideloads the malicious DLL.” The malware family can also enable the following nasty outcomes: Bitdef...

Read full article

Affected Software

4 affected components
Bitdefender EggStreme Framework
Bitdefender EggStremeFuel
Bitdefender EggStremeLoader
Bitdefender EggStremeRef
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of the article?

The article discusses a strain of in-memory malware known as 'EggStreme' that is believed to be linked to Chinese advanced persistent threat groups targeting a military company in the Philippines.

2

What are the security implications mentioned in the article?

The article highlights concerns over persistent access and potential espionage by state-sponsored threat actors through sophisticated malware.

3

What type of malware is identified in the article?

The malware identified in the article is an advanced form of in-memory malware designed for stealth and persistent access.

4

Which security products are associated with the malware discussed?

The affected products associated with the malware are Bitdefender's EggStreme Framework, EggStremeFuel, EggStremeLoader, and EggStremeRef.

5

Who is likely responsible for the 'EggStreme' malware attacks?

The article suggests that the attacks are likely conducted by advanced persistent threat groups from China.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203