Executive Summary
In September 2025, a Chinese advanced persistent threat (APT) group breached a Philippines-based military company using a sophisticated multi-stage attack leveraging the novel fileless malware framework, EggStreme. According to Bitdefender, the attackers achieved persistence and stealth by injecting their malicious code directly into memory and utilizing DLL sideloading to execute payloads without writing files to disk. This allowed them to maintain an undetected presence, conduct espionage, and potentially exfiltrate sensitive military and government data. The breach underscores ongoing risks to national security organizations from highly resourced nation-state actors employing advanced techniques.
This incident highlights the emergence of more evasive, memory-resident malware frameworks targeting defense and critical infrastructure. Fileless attack methods such as those used by EggStreme are increasingly common and harder to detect, urging organizations to adopt advanced threat detection, improved segmentation, and robust incident response capabilities.
Why This Matters Now
The rise of fileless and memory-resident malware, specifically targeting sensitive government and military sectors, marks a significant evolution in APT tactics. Immediate attention is needed to counter stealthy attacks bypassing traditional endpoint defenses, as these methods can silently undermine national security and disrupt critical operations.
Attack Path Analysis
The Chinese APT gained initial access by exploiting a vulnerability or misconfiguration to deploy EggStreme fileless malware via DLL sideloading. Once inside, the attacker escalated privileges, likely leveraging in-memory code execution for stealth. With elevated access, they moved laterally across internal military systems, evading traditional detection by using encrypted and fileless techniques. Persistent command and control was established over encrypted channels, allowing ongoing remote management. Sensitive military data was exfiltrated through covert and potentially encrypted channels. The impact phase involved long-term espionage and ongoing unauthorized access to sensitive Philippine military resources.
Kill Chain Progression
Initial Compromise
Description
The attacker used DLL sideloading and fileless malware to gain access, likely exploiting a vulnerable service or spear-phishing a user.
Related CVEs
CVE-2017-8570
CVSS 7.8A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory.
Affected Products:
Microsoft Office – 2010, 2013, 2016
Exploit Status:
exploited in the wildCVE-2018-20250
CVSS 7.8WinRAR before 5.70 allows remote attackers to execute arbitrary code via crafted ACE archives, as demonstrated by a file extraction to the Startup folder.
Affected Products:
RARLAB WinRAR – < 5.70
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Process Injection: DLL Injection
Application Layer Protocol: Web Protocols
Exploit Public-Facing Application
Event Triggered Execution: Installer Packages
Signed Binary Proxy Execution: Rundll32
Input Capture: Keylogging
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Authentication for Personnel and Vendors
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Pillar 2: Identity
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Defense/Space
Chinese APT's EggStreme fileless malware directly compromised Philippines military systems, exploiting DLL sideloading for persistent espionage requiring enhanced zero trust segmentation.
Government Administration
Advanced persistent threats targeting military infrastructure pose critical risks to government operations, demanding improved east-west traffic security and threat detection capabilities.
Computer/Network Security
Undocumented fileless malware frameworks bypass traditional detection methods, highlighting urgent need for inline IPS and anomaly detection to combat memory-based attacks.
Information Technology/IT
Multi-stage toolsets leveraging DLL sideloading expose IT infrastructure vulnerabilities, requiring comprehensive multicloud visibility and encrypted traffic protection against APT infiltration.
Sources
- Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systemshttps://thehackernews.com/2025/09/chinese-apt-deploys-eggstreme-fileless.htmlVerified
- China-related threat actors deployed a new fileless malware against the Philippines militaryhttps://www.techradar.com/pro/security/china-related-threat-actors-deployed-a-new-fileless-malware-against-the-philippines-militaryVerified
- Fileless EggStreme Malware Campaign Attributed to Chinese APT Against Military Organisationshttps://cybersecsentinel.com/fileless-eggstreme-malware-campaign-attributed-to-chinese-apt-against-military-organisations/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcement of Zero Trust segmentation, inline threat detection, encrypted east-west and egress controls, and unified cloud visibility would have significantly constrained the attack, limiting both the stealthy lateral movement and covert data exfiltration stages. CNSF-aligned controls deliver fine-grained isolation and real-time inspection to detect and disrupt fileless and encrypted threat activity as described in the incident.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous fileless injection and unusual traffic patterns.
Control: Zero Trust Segmentation
Mitigation: Limits the scope of compromise and restricts access to sensitive resources.
Control: East-West Traffic Security
Mitigation: Blocks or alerts on unauthorized service-to-service and region-to-region communications.
Control: Cloud Firewall (ACF) & Inline IPS (Suricata)
Mitigation: Detection and disruption of known C2 signatures and suspicious encrypted outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound data transfers via policy-based filtering and real-time monitoring.
Centralized monitoring and cross-cloud policy ensure rapid containment and remediation.
Impact at a Glance
Affected Business Functions
- Military Operations
- Intelligence Gathering
- Command and Control Systems
Estimated downtime: 14 days
Estimated loss: $5,000,000
Potential exposure of classified military documents, strategic plans, and intelligence reports.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation and microsegmentation to isolate sensitive workloads and restrict attack paths.
- • Enable inline threat detection and anomaly response to identify memory-based and fileless attacks early.
- • Enforce east-west traffic controls and continuous egress policy inspection across all workloads and regions.
- • Deploy adaptive cloud firewalls and inline IPS to disrupt command and control and rapidly block new threats.
- • Strengthen multicloud visibility, automated incident response, and centralized governance to reduce dwell time and response lag.



