The Eagerbee malware framework has evolved, with new variants targeting government organizations and internet service providers (ISPs) in the Middle East. Recent investigations uncovered sophisticated components fueling these attacks, including a newly designed service injector. This injector stealthily embeds the backdoor into active system services, enhancing its persistence and evasion capabilities. In addition to the service injector, researchers have identified previously undocumented plugins that are deployed after the backdoor is installed. These plugins enable a wide array of malicious actions, such as deploying additional payloads, probing file systems, executing command shells, and more.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox