s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.more_eggs

📛 Threat Title

Malware family: More_eggs

Category: More_eggs First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.more_eggs`. Printable name: More_eggs. Aliases: SpicyOmelette,SKID.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable " More_eggs " being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4. [1] [2]

  • web:community.gurucul.com

    A customer's talent search resulted in their recruitment officer downloading a fraudulent resume and unintentionally running a malicious .LNK file, leading to a More_eggs infection. More_eggs is a JScript backdoor associated with the Golden Chickens malware -as-a-service (MaaS) toolkit.

  • web:cyberpress.org

    The threat landscape continues to evolve as the financially motivated Venom Spider group also known as Golden Chickens intensifies the spread of the More_Eggs malware , a JavaScript-based backdoor distributed via Malware -as-a-Service (MaaS). Recent campaigns have heightened their focus on human resources (HR) departments, leveraging the guise of legitimate job application emails to deliver ...

  • web:cybersecuritynews.com

    The More_Eggs malware , a sophisticated JavaScript backdoor operated by the financially motivated Venom Spider (also known as Golden Chickens) threat group, has emerged as a significant threat to corporate environments. This backdoor is particularly concerning as it's distributed through a Malware -as-a-Service (MaaS) model to various threat actors, including notorious groups like FIN6 and ...

  • web:malpedia.caad.fkie.fraunhofer.de

    More_eggs is a JavaScript backdoor used by the Cobalt group. It attempts to connect to its C&C server and retrieve tasks to carry out, some of which are: - d&exec = download and execute PE file - gtfo = delete files/startup entries and terminate - more_eggs = download additional/new scripts - more_onion = run new script and terminate current ...

  • web:radicl.com

    A write-up by The DFIR Report on the More_Eggs malware is particularly intriguing due to its sophisticated infection techniques and use of local binaries.

  • web:thehackernews.com

    A new phishing attack distributing More_eggs malware is targeting recruiters by posing as job applicants on LinkedIn.

  • web:www.securityblue.team

    By dissecting the " More_eggs " backdoor and analyzing their use of several initial access files and also the " More_eggs " JavaScript malware , we have uncovered the intricate methods they employ to infiltrate targets and harvest sensitive information.

  • web:www.trendmicro.com

    A customer's talent search led to their recruitment officer downloading a fake resume and inadvertently executing a malicious .LNK file, resulting in a more_eggs infection (Figure 1). More_eggs is a JScript backdoor that belongs to the Golden Chickens malware -as-a-service (MaaS) toolkit.

  • web:zerosecurity.org

    Upon execution, the LNK file triggers a series of obfuscated commands, ultimately leading to the deployment of the More_eggs backdoor. This sophisticated malware , sold as a Malware -as-a-Service (MaaS) offering, is capable of stealing a wide range of credentials, including those for online bank accounts, email services, and IT administrator access.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.