Skip to main content

EggStreme Malware: Inside a New APT Framework Targeting the Philippine Military

N2K NetworksJanuary 10, 202629 min241 views
25 connections·40 entities in this video→

Unpacking the EggStreme Malware Framework

  • πŸ’‘ The EggStreme malware is a sophisticated, multi-stage framework developed by an Advanced Persistent Threat (APT) group, designed for long-term espionage.
  • 🎯 Each component of the framework has a specific, small goal, making detection difficult until all parts are combined to reveal its powerful capabilities.
  • πŸ” The name "EggStreme" originated from internal naming conventions for its various components, such as EggStreme Fuel, EggStreme Loader, and EggStreme Agent, though the exact origin of the name is unclear.

Fileless Execution and Detection Challenges

  • 🧠 Fileless malware execution means the malicious code does not touch the disk; instead, it runs in memory, often injected into legitimate processes.
  • ⚠️ This fileless nature presents significant detection challenges, as scanning memory is resource-intensive for endpoint security solutions.
  • πŸ›‘οΈ EggStreme specifically targets legitimate processes for injection, such as Microsoft Defender or explorer.exe, making its behavior harder to distinguish from normal system activity.

Infection Chain and DLL Sideloading

  • ❓ The initial access vector for EggStreme remains unknown, likely occurring years prior to discovery, with the first detected sign being the deployment of a legitimate Windows executable, vinmail.exe.
  • 🧩 Attackers paired vinmail.exe with a malicious DLL, mscore_svc.dll, in the same directory, exploiting DLL sideloading.
  • πŸ“ˆ This technique abuses how executables load libraries, causing them to load the malicious DLL instead of the legitimate one, a common tactic among Chinese APT groups.

EggStreme Agent and Capabilities

  • βš™οΈ The final payload, the EggStreme Agent, supports approximately 58 commands for system fingerprinting, reconnaissance, privilege escalation, data exfiltration, and lateral movement.
  • πŸ’» Commands are numerical IDs, with the Command and Control server sending numbers to instruct the agent, ranging from basic information gathering to advanced execution techniques.
  • πŸ”‘ The framework also deploys an EggStreme Keylogger which monitors keystrokes, clipboard data, and exfiltrates sensitive information, often injected into new user sessions.

Persistence and Stealth Techniques

  • πŸ› οΈ Attackers achieved persistence by hijacking legitimate, but disabled or manually set, Windows services like Group Policy Software Deployment and iSCSI service.
  • πŸ“„ They manipulated these services by redirecting DLL loading paths or replacing DLL files, often with minor alterations (e.g., adding a single letter to a filename) to evade detection.
  • πŸ”„ A loader component, executed every 10 minutes, reads an encrypted file containing multiple malware components, extracting and reflecting them into memory.

Threat Actor Sophistication and Recommendations

  • πŸš€ The development of EggStreme from scratch, utilizing advanced techniques like DLL sideloading and in-memory execution, indicates a very high level of sophistication.
  • πŸ‡¨πŸ‡³ While attribution to a specific group is difficult due to shared tactics among Chinese APTs, the targeting of a Philippine military company aligns with Chinese geopolitical interests.
  • πŸ›‘οΈ Security teams should focus on defense-in-depth, proactively blocking Living Off The Land (LOTL) techniques, ensuring robust detection and response (EDR/XDR) capabilities, and critically, monitoring alerts with skilled personnel to act on red flags.
Knowledge graph40 entities Β· 25 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters11 moments

Key Moments

Transcript107 segments

Full Transcript

Topics14 themes

What’s Discussed

EggStreme MalwareAPT FrameworkDLL SideloadingFileless MalwareIn-Memory ExecutionLiving Off The LandEndpoint Detection and Response (EDR)Advanced Persistent Threat (APT)Cyber EspionageMalware AnalysisThreat IntelligencePhilippine MilitaryBitdefenderWindows Services Abuse
Smart Objects40 Β· 25 links
ProductsΒ· 19
CompaniesΒ· 7
PersonΒ· 1
ConceptsΒ· 10
MediasΒ· 2
LocationΒ· 1