EagerBee
Aliases: Thumtais
- First seen
- 2018-06-01 00:00:00
- Malware type
- loader, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:07:09
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
According to Elastic, EagerBee loads additional capabilities using remotely-downloaded PE files, hosted in C2. However, its implementation and coding practices reveal a lack of advanced skills from the author, relying on basic techniques. During their research, they identified string formatting and underlying behavior that aligns with previous research attributed to a Chinese-speaking threat actor referred to as LuckyMouse (APT27, EmissaryPanda).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Eagerbee_Auto (yara-rule)
Reports & references
- elastic.co — Introducing The Ref5961 Intrusion Set (report)
- Kaspersky — 115175 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Eagerbee (report)
- lac.co.jp — 20250514 004379 (report)
- lac.co.jp — 20240605 004019 (report)