EagerBee

Aliases: Thumtais

First seen
2018-06-01 00:00:00
Malware type
loader, backdoor
Family
Malware family
Profile updated
2026-07-07 13:07:09

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

According to Elastic, EagerBee loads additional capabilities using remotely-downloaded PE files, hosted in C2. However, its implementation and coding practices reveal a lack of advanced skills from the author, relying on basic techniques. During their research, they identified string formatting and underlying behavior that aligns with previous research attributed to a Chinese-speaking threat actor referred to as LuckyMouse (APT27, EmissaryPanda).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Eagerbee_Auto (yara-rule)

Reports & references

  • elastic.co — Introducing The Ref5961 Intrusion Set (report)
  • Kaspersky — 115175 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Eagerbee (report)
  • lac.co.jp — 20250514 004379 (report)
  • lac.co.jp — 20240605 004019 (report)

External references