TF-MAL-js.more_eggs
📛 Threat Title
Malware family: More_eggs
Description
ThreatFox malware family `js.more_eggs`. Printable name: More_eggs. Aliases: SpicyOmelette,SKID.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable " More_eggs " being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4. [1] [2]
-
web:community.gurucul.com
A customer's talent search resulted in their recruitment officer downloading a fraudulent resume and unintentionally running a malicious .LNK file, leading to a More_eggs infection. More_eggs is a JScript backdoor associated with the Golden Chickens malware -as-a-service (MaaS) toolkit.
-
web:cyberpress.org
The threat landscape continues to evolve as the financially motivated Venom Spider group also known as Golden Chickens intensifies the spread of the More_Eggs malware , a JavaScript-based backdoor distributed via Malware -as-a-Service (MaaS). Recent campaigns have heightened their focus on human resources (HR) departments, leveraging the guise of legitimate job application emails to deliver ...
-
web:cybersecuritynews.com
The More_Eggs malware , a sophisticated JavaScript backdoor operated by the financially motivated Venom Spider (also known as Golden Chickens) threat group, has emerged as a significant threat to corporate environments. This backdoor is particularly concerning as it's distributed through a Malware -as-a-Service (MaaS) model to various threat actors, including notorious groups like FIN6 and ...
-
web:malpedia.caad.fkie.fraunhofer.de
More_eggs is a JavaScript backdoor used by the Cobalt group. It attempts to connect to its C&C server and retrieve tasks to carry out, some of which are: - d&exec = download and execute PE file - gtfo = delete files/startup entries and terminate - more_eggs = download additional/new scripts - more_onion = run new script and terminate current ...
-
web:radicl.com
A write-up by The DFIR Report on the More_Eggs malware is particularly intriguing due to its sophisticated infection techniques and use of local binaries.
-
web:thehackernews.com
A new phishing attack distributing More_eggs malware is targeting recruiters by posing as job applicants on LinkedIn.
-
web:www.securityblue.team
By dissecting the " More_eggs " backdoor and analyzing their use of several initial access files and also the " More_eggs " JavaScript malware , we have uncovered the intricate methods they employ to infiltrate targets and harvest sensitive information.
-
web:www.trendmicro.com
A customer's talent search led to their recruitment officer downloading a fake resume and inadvertently executing a malicious .LNK file, resulting in a more_eggs infection (Figure 1). More_eggs is a JScript backdoor that belongs to the Golden Chickens malware -as-a-service (MaaS) toolkit.
-
web:zerosecurity.org
Upon execution, the LNK file triggers a series of obfuscated commands, ultimately leading to the deployment of the More_eggs backdoor. This sophisticated malware , sold as a Malware -as-a-Service (MaaS) offering, is capable of stealing a wide range of credentials, including those for online bank accounts, email services, and IT administrator access.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.