ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

More_eggs Malware Spread via Fake Resumes to HR Departments

Cybercriminals Exploit Job Application Process to Deploy Dangerous Backdoor

Kyle by Kyle
October 2, 2024
in Malware
Reading Time: 3 mins read
More eggs a Javascript backdoor targets HR departments everywhere
Share on FacebookShare on Twitter

Cybersecurity researchers have uncovered a sophisticated spear-phishing campaign targeting HR professionals with a potent JavaScript backdoor known as More_eggs. This latest attack, observed in late August 2024, highlights the persistent efforts of threat actors to exploit the job application process for malicious purposes.

The Anatomy of the Attack

According to an analysis by Trend Micro researchers Ryan Soliven, Maria Emreen Viray, and Fe Cureg, the attack began with a carefully crafted spear-phishing email sent to a talent search lead in the engineering sector. The email, designed to build trust and confidence, set the stage for the next phase of the attack.

Shortly after the initial contact, a recruitment officer downloaded what appeared to be a resume file named “John Cboins.zip” from a suspicious URL using Google Chrome. While the exact source of the URL remains unclear, investigators noted that both targeted users were actively searching for an inside sales engineer at the time of the attack.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The Deceptive Download

The malicious URL, johncboins[.]com, featured a prominent “Download CV” button, enticing victims to download a ZIP archive containing a Windows shortcut (LNK) file. This method of distribution bears striking similarities to a previous campaign disclosed by eSentire in June, which utilized LinkedIn as a vector for spreading fake resumes hosted on attacker-controlled sites.

MDR More eggs Backdoor Fig4
Personal website of a fictitious “John Cboins”. Credits: Trend Micro

More_eggs: A Potent Threat

Upon execution, the LNK file triggers a series of obfuscated commands, ultimately leading to the deployment of the More_eggs backdoor. This sophisticated malware, sold as a Malware-as-a-Service (MaaS) offering, is capable of stealing a wide range of credentials, including those for online bank accounts, email services, and IT administrator access.
More_eggs is attributed to a threat actor known as the Golden Chickens group (also called Venom Spider) and has been utilized by several notorious e-crime groups, including FIN6 (ITG08), Cobalt, and Evilnum.

The Infection Process

Once activated, More_eggs performs a series of actions:

  1. Checks for admin or user privileges
  2. Conducts reconnaissance on the compromised host
  3. Establishes communication with a command-and-control (C2) server
  4. Receives and executes secondary malware payloads

Trend Micro researchers also observed a variant of the campaign that incorporates PowerShell and Visual Basic Script (VBS) components in the infection chain, demonstrating the adaptability of the threat actors.

Attribution Challenges

While the tactics, techniques, and procedures (TTPs) employed in this attack bear similarities to those used by the FIN6 group, definitively attributing the campaign to a specific threat actor remains challenging. The nature of the Malware-as-a-Service model allows multiple groups to leverage the same toolkits and infrastructure, complicating attribution efforts.

Wider Implications: The PackXOR Connection

In a related development, French cybersecurity firm HarfangLab recently uncovered PackXOR, a private packer used by the FIN7 cybercrime group to encrypt and obfuscate their AvNeutralizer tool. Intriguingly, PackXOR has also been observed protecting unrelated payloads such as the XMRig cryptocurrency miner and the r77 rootkit, suggesting its potential use by other threat actors.

Protecting Against Spear-Phishing Attacks

As these sophisticated campaigns continue to target HR professionals and recruiters, organizations must prioritize cybersecurity awareness and implement robust defensive measures. Key steps include:

  • Providing comprehensive security training for all employees, especially those handling job applications
  • Implementing advanced email filtering and malware detection systems
  • Regularly updating and patching all software and systems
  • Enforcing strong access controls and multi-factor authentication
  • Conducting regular security audits and penetration testing
Tags: Spear phishing
Previous Post

Rackspace Thwarts Cyber Intrusion Exploiting Zero-Day Vulnerability

Next Post

Linux Malware “Perfctl” Exploits Vulnerabilities (CVE-2023-33246) and Misconfigurations

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.