Contact

EAGERBEE, with updated and novel components, targets the Middle East

NetmanageIT OpenCTI - opencti.netmanageit.com

EAGERBEE, with updated and novel components, targets the Middle East



SUMMARY :

The EAGERBEE backdoor, deployed at ISPs and governmental entities in the Middle East, has been analyzed to reveal new components and capabilities. The malware uses a novel service injector to inject the backdoor into running services, and employs several plugins for various malicious activities. The initial infection vector remains unclear, but some organizations were breached via the ProxyLogon vulnerability. The analysis uncovered potential links between EAGERBEE and the CoughingDown threat group, including code similarities and overlapping command and control infrastructure. The malware's memory-resident architecture and ability to inject code into legitimate processes enhance its stealth capabilities, making detection challenging.

OPENCTI LABELS :

coughingdown,dllloader1x64.dll,powershell,proxylogon,ssl


Open in NetmanageIT OpenCTI Public Instance with below link!


Use public read only username and password on login page.

NOTE : Use Public READ only user credentials on login page banner.


EAGERBEE, with updated and novel components, targets the Middle East