EggStreme is a malware framework/loader reported in a year-long cyber attack against a Philippine military company and attributed in the provided content to a China-linked government-backed APT. It is described as fileless malware that decrypts payloads on the fly for in-memory execution, a technique intended to reduce on-disk artifacts and evade detection. The malware reportedly leverages legitimate Windows services for persistence and lateral movement. The cited targeting is defense-related, specifically Philippine military systems or a Philippine military company. High-confidence behaviors mentioned in the content are: on-the-fly payload decryption, in-memory execution, use of legitimate Windows services, persistence, and lateral movement. No specific indicators of compromise such as hashes, domains, IPs, filenames, or mutexes are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage fileless malware framework used for low-profile espionage; injects code into memory and uses DLL sideloading for execution/persistence (per excerpt).
EggStreme is a multi-stage malware framework/backdoor used by Chinese APTs to establish persistent access, inject payloads, and facilitate lateral movement within victim networks.
A loader used by Chinese APTs to decrypt and execute payloads in memory, supporting fileless malware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.