New variants of the Eagerbee backdoor have been spotted targeting government entities and ISPs in the Middle East.Kaspersky researchers discovered new attack components, including a service injector and plugins for payload delivery and remote control.The backdoor injects itself into the Themes service, gathers system information, and communicates with a command and control (C2) server.The backdoor uses plugins to handle file and process management, remote access, service control, and network monitoring.