EAGERBEE Malware

General News

Summary

A newly updated version of the EAGERBEE malware framework has been observed targeting Internet Service Providers (ISPs) and government organizations in the Middle East. This latest iteration, also known as Thumtais, includes a range of components that enable it to deploy additional payloads, explore file systems, and execute command shells. Later investigations revealed that a modified version of EAGERBEE was deployed in cyber espionage campaigns attributed to a Chinese state-affiliated threat actor known as Cluster Alpha. Notably, BackdoorDiplomacy shares tactical characteristics with CloudComputating (also called Faking Dragon), a Chinese-speaking entity linked to a modular malware framework known as QSC. By injecting unsafe code into legitimate processes, it conceals its command shell activities, seamlessly blending with normal system functions and complicating efforts to detect and analyze its behavior.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M