Researchers reported continued development of the EAGERBEE backdoor, also tracked as Thumtais, in espionage campaigns attributed to China-linked operators targeting government and private-sector organizations in Japan, Southeast Asia, Mongolia, and the Middle East. Recent investigations tied the malware to intrusion activity associated with REF5961 and overlaps with TA428/LuckyMouse, while also noting possible links to Tonto Team. Earlier incidents included compromise of a foreign affairs ministry in an ASEAN state and a Japanese consulting company, where EAGERBEE appeared alongside other implants such as RUDEBIRD and DOWNTOWN and was delivered through DLL hijacking or sideloading chains.
Newer EAGERBEE variants add capabilities aimed at persistence, stealth, and flexible command-and-control, including listen-mode operation that opens ports on infected hosts for inbound C2, encrypted configuration and communications, authenticated proxy support, and in-memory execution of downloaded payloads. Researchers also observed deployment of WinDivert to interfere with DNS lookups for security vendor domains and identified related tooling such as OAED Loader delivering the Go-based NKN-goRAT, which uses the decentralized NKN network for C2; defenders were advised to watch for unusual Windows services, newly opened TCP/UDP ports, dropped files, and traffic to seed.nkn.org over TCP/30003.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On May 14, 2025, LAC published follow-on research describing newly observed EAGERBEE variants that use listen mode and encryption, and noting targeting expansion into the Middle East and Russia. The report also revised attribution by assessing that multiple China-based groups use EAGERBEE, with confirmed links to Tonto Team and REF5961 and possible ties to TA428/LuckyMouse.
On June 5, 2024, LAC published a report on Thumtais/EAGERBEE targeting Japanese organizations, centered on the February 2023 consulting-company intrusion. The report documented newer variants with WinDivert-based DNS interference and authenticated-proxy support, and assessed links to TA428/LuckyMouse.
LAC stated that OAED Loader also appeared in 2024 attacks targeting Russia. The same report connected newer encrypted EAGERBEE variants mainly to attacks against Russia.
LAC reported that since 2024, EAGERBEE attacks have also been observed in the Middle East. This represented a geographic expansion beyond the malware's earlier concentration in Asia.
Elastic Security Labs published research on October 4, 2023 introducing the REF5961 intrusion set targeting an ASEAN foreign affairs ministry and assessing it as China-nexus espionage. The report disclosed EAGERBEE, RUDEBIRD, and DOWNTOWN and linked EAGERBEE to prior activity overlapping with LuckyMouse/APT27 and TA428.
LAC observed a targeted cyberattack against a Japanese consulting company in February 2023 using Thumtais/EAGERBEE and additional malware written in Cython, Go, and Nim. LAC assessed the operation was likely conducted by a China-linked threat actor.
LAC said OAED Loader, a DLL malware loader used by Tick and Tonto Team, appeared in a campaign against Japan in February 2023. In later analysis, OAED Loader was noted as delivering a new RAT called NKN-goRAT in an observed case.
Elastic reported a Mongolia-themed lure document referencing the Billion Trees National Movement Fund that was likely created in September 2022. The lure was tied to a Mongolia-focused campaign associated with EAGERBEE-related activity.
LAC reported that Thumtais, also known as EAGERBEE, has been continuously used in attacks since around May 2022. A later LAC report also described EAGERBEE campaigns as having been observed since around 2022.
LAC stated that EAGERBEE-related attacks were observed broadly across Asia from late 2022 to late 2023. This marked the malware's early regional spread before later expansion into other regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
lac.co.jp
Open sourcelac.co.jp
Open sourceelastic.co
Open sourcesecurelist.com
Open sourcemacnica.co.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.