meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Sunny-side spyware. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 27 September 2025

⏱️ 25 minutes

🧾️ Download transcript

Summary

This week, we are joined by Martin Zugec, Technical Solutions Director from Bitdefender, sharing their work and findings on "EggStreme Malware: Unpacking a New APT Framework Targeting a Philippine Military Company. A newly identified Chinese APT group has been observed deploying a sophisticated, fileless malware framework called EggStreme against a Philippine military company. The multi-stage toolkit uses DLL sideloading and in-memory execution to evade detection, with its core backdoor, EggStremeAgent, enabling reconnaissance, lateral movement, keylogging, and data theft. Researchers note the campaign’s persistence and stealth highlight professional, geopolitically motivated espionage activity linked to Chinese national interests. The research can be found here: EggStreme Malware: Unpacking a New APT Framework Targeting a Philippine Military Company Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

AI adoption is exploding, and security teams are under pressure to keep up.

0:16.9

That's why the industry is coming together at the Datasec AI conference, the premier event for cybersecurity data and AI leaders, hosted by data security leader, Saira.

0:27.6

Built for the industry, by the industry, this two-day conference is where real-world insights and bold solutions take center stage.

0:35.6

Datasec AI 25 is happening November 12th and 13th in Dallas.

0:41.8

There's no cost to attend.

0:43.4

Just bring your perspective and join the conversation.

0:46.7

Register now at Datasek AI 2025.com backslash cyberwire.

0:52.7

Thank you. dot com backslash cyberwire. Hello everyone and welcome to the CyberWire's Research Saturday.

1:07.3

I'm Dave Bittner and this is our weekly conversation with researchers and analysts

1:11.6

tracking down the threats and vulnerabilities, solving some of the hard problems and protecting

1:16.6

ourselves in a rapidly evolving cyberspace.

1:19.6

Thanks for joining us.

1:21.6

Is it new activity, Is it existing activity? Is it a cluster of victims or is it isolated case?

1:35.1

So in the case of curly comrades, we started tracking this group in mid-2020.

1:42.3

That's Martin Zujik, technical solutions director at Bit Defender.

1:47.0

The research we're discussing today is titled Curly Comrades,

1:50.0

a new threat actor targeting geopolitical hotbeds.

1:58.0

It's one of those things that people probably don't know.

2:05.9

Research like this very often takes months.

2:09.3

So it's normal when you see it released, let's say, half a year later.

2:13.0

That's perfectly fine because we are documenting all the tools they are using, all the servers,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.