Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new phishing attack has been identified distributing the More_eggs malware disguised as Curriculum Vitae. More_eggs, a modular backdoor, is capable of harvesting sensitive information and is offered under a Malware-as-a-Service (MaaS) model.  

Impact

More_eggs malware is likely to have a significant impact on the recruitment sector. This is due to its advanced capabilities and sophisticated evasion techniques. The malware can cause significant operational disruptions, financial losses, and damage to reputation. The deployment of ransomware can lead to data encryption and demands for ransom payments. 

Exploitation

Threat actors send phishing emails disguised as job applications, often targeting recruiters and HR departments. These emails contain links to fake resume download sites. A malicious Windows Shortcut file (LNK) is downloaded once the victim clicks on the link. This retrieves and executes a malicious DLL file, establishing persistence on the victim’s system, allowing the threat actors to maintain access. The malware collects sensitive information from the infected system. Additionally, it can download and execute supplementary malicious payloads.    

Containment, Mitigations & Remediations

Remediation steps for addressing the More_eggs malware include: 

  • Disconnect infected systems from the network to prevent further spread 
  • Use reputable antivirus and anti-malware tools to detect and remove the malware 
  • Change all passwords and credentials that may have been compromised 
  • Apply all available security patches and updates to prevent future vulnerabilities 
  • Educate employees about phishing attacks and safe email practices. 

Threat Landscape

The risk level to the recruitment sector from the More_eggs malware is likely to be high due to targeted phishing attacks, sensitive data exposure, operational disruptions, financial impact, and potential reputation damage. 

The primary motivation behind More_eggs attacks is financial gain, through data theft, unauthorised transactions, and extortion. It primarily targets financial institutions, cryptocurrency entities, and corporate entities involved in financial operations.  

The malware has a modular design, allowing it to adapt and evolve, making it a versatile and persistent threat. By using obfuscated code and complex infection chains, it can bypass traditional security measures and evade detection. 

Threat Group

The More_eggs malware campaign is primarily attributed to the Venom Spider threat group. Emerging in 2018, it is known for its sophisticated cyber-attacks, particularly targeting HR departments with phishing emails disguised as job applications.  

Venom Spider is financially motivated and operates under a MaaS model, allowing it to transcend geopolitical borders. It is known to operate globally, leveraging online platforms like LinkedIn to reach its targets.  

The group is considered dangerous due its sophisticated cyber-attacks and the use of advanced malware like More_eggs. It poses significant risks to organisations with phishing emails, harvesting sensitive data, and deploying additional malicious payloads. 

Further Information

The Hacker News article 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content