EAGERBEE, also known as Thumtais, is a Windows backdoor framework used in targeted cyberespionage operations against government entities, internet service providers, and other organizations in Asia, the Middle East, and Russia. First observed in 2023, it supports outbound and passive-listening command-and-control modes, optional TLS, proxy-aware communications, host profiling, and in-memory execution of remotely supplied 64-bit PE payloads.
EAGERBEE variants use dynamic API resolution, encrypted or XOR-obfuscated configuration data, mutex-based single-instance control, and memory-resident execution to reduce detection. A service-injector component abuses DLL hijacking and legitimate Windows services to inject the backdoor into service processes. The framework can establish service-based persistence and includes a plugin orchestrator that loads, invokes, unloads, and removes plugins in memory.
Documented plugins provide file and directory enumeration and manipulation, process and service management, network-connection discovery, command-shell execution, payload injection, and remote-access functions including RDP enablement. Some variants can disrupt DNS resolution or communications involving security-vendor infrastructure. EAGERBEE activity has been associated with DLL sideloading, and earlier East Asian intrusions linked EAGERBEE deployment to exploitation of Microsoft Exchange ProxyLogon vulnerability CVE-2021-26855 followed by web-shell use.
EAGERBEE has been linked with confidence to China-nexus espionage activity, including REF5961 and Operation Crimson Palace-related activity. Code, infrastructure, and operational overlaps have also been reported with LuckyMouse/APT27, TA428-related tooling, Tonto Team activity, and the CoughingDown threat group; these relationships do not establish exclusive ownership, and the malware appears to have been used by multiple China-based operator groups.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Two of these organizations were breached via the infamous ProxyLogon vulnerability (CVE-2021-26855) in Exchange servers, after which malicious webshells were uploaded and utilized to execute commands on the breached servers. | In our recent investigation into the EAGERBEE backdoor, we found that it was being deployed at ISPs and governmental entities in the Middle East.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Eagerbee is an advanced backdoor malware used in targeted attacks against Internet Service Providers (ISPs) and government entities in the Middle East. It operates primarily in memory and uses a service injector and plugins for persistence, command execution, collection, and C2 communications.
EAGERBEE is a newly identified backdoor discovered by Elastic Security Labs that loads additional capabilities using remotely-downloaded PE files, hosted in C2.
EAGERBEE is a newly identified backdoor discovered by Elastic Security Labs that loads additional capabilities using remotely-downloaded PE files, hosted in C2.
EAGERBEEは、Microsoft Visual C/C++で開発されたダウンローダ型マルウェアであり、C2サーバからダウンロードしたファイルをメモリ上で実行する機能を備えています。
EAGERBEEは、Microsoft Visual C/C++で開発されたダウンローダ型マルウェアであり、C2サーバからダウンロードしたファイルをメモリ上で実行する機能を備えています。
EAGERBEEは、Microsoft Visual C/C++で開発されたダウンローダ型マルウェアであり、C2サーバからダウンロードしたファイルをメモリ上で実行する機能を備えています。
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Annex B lists Execution: “T1059.003 Command and Scripting Interpreter: Windows Command Shell.”
“The latest version of EAGERBEE features a novel service injector designed to inject the backdoor into a running service.”
The C2 addresses are either hardcoded values or stored in an XOR-encrypted file named c:\users\public\iconcache.mui.
EAGERBEE dynamically constructs its Import Address Table (IAT) during runtime; RUDEBIRD resolves imports dynamically by walking the TEB/PEB and loaded modules.
“EAGERBEE appears on the infected system as ‘dlloader1x64.dll’.” Annex B lists “T1036.005 Masquerading: Match Legitimate Name or Location.”
“The latest version of EAGERBEE features a novel service injector designed to inject the backdoor into a running service.”
The sample's operational schedule is controlled by the string '0-5:00:23;6:00:23;' and allows the malware to impose self-restrictions during specific timeframes.
attrib . exe + s + h + a C : \ users \ public \ ntusers0 . dat ... attrib . exe + s + h + a system32 \ tsvipsrv . dll
“Upon installing and running the payload, the service injector targets legitimate windows services ... to write the backdoor payload in memory via DLL hijacking.”
The backdoor retrieves the proxy host and port information for the current user by reading the registry key Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer.
“[Eagerbee] initiates the collection of information such as operating system characteristics and network addresses.” Annex B lists “T1016 System Network Configuration Discovery.”
The module also collects user accounts associated with the processes.
Annex B lists Discovery: “T1049 System Network Connections Discovery.”
It then collects details about all running processes on the system, including: Process identifiers; The number of execution threads started by each process; The identifier of the parent process; The fully qualified path of each process executable.
EAGERBEE gathers the computer name, Windows version, GUID, processor architecture, and Windows product/build details. RUDEBIRD enumerates hostname, username, IP address, architecture, and current-user privilege.
Reverseモードでは、マルウェアが実行されるとコールバック通信を発生させ、感染端末からC2サーバへ接続します。一方、Listenモードでは、感染端末のポートを開放し、C2サーバからの通信を待ち受けます
RUDEBIRD communicates using HTTPS. EAGERBEE can initialize a proxy by sending a CONNECT request.
EAGERBEE detects HTTP proxy configuration through the ProxyEnable and ProxyServer registry keys, then sends a CONNECT request to the configured proxy destination.
High prioritization of evasive tactics and tools: ... overwriting ntdll.dll in memory to unhook the Sophos AV agent process from the kernel, abusing AV software for sideloading... Deployment of new EAGERBEE malware variants with updated capability of modifying packets to disrupt security agent network communications.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor framework with modular components for payload deployment, filesystem enumeration, and command execution; updated variant targeting ISPs and government entities in the Middle East.
A modular backdoor framework used to compromise targets, execute commands, enumerate file systems, and deploy additional payloads.
A Chinese-nexus malware family whose newer variants were used to infect services, establish C2, and modify DNS traffic via WinDivert to block communications with security vendor infrastructure.
Referenced as malware previously seen in related Cluster Alpha activity that could potentially be used to block endpoint telemetry and updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.