Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new phishing attack has been identified distributing the More_eggs malware disguised as Curriculum Vitae. More_eggs, a modular backdoor, is capable of harvesting sensitive information and is offered under a Malware-as-a-Service (MaaS) model.
Impact
More_eggs malware is likely to have a significant impact on the recruitment sector. This is due to its advanced capabilities and sophisticated evasion techniques. The malware can cause significant operational disruptions, financial losses, and damage to reputation. The deployment of ransomware can lead to data encryption and demands for ransom payments.
Exploitation
Threat actors send phishing emails disguised as job applications, often targeting recruiters and HR departments. These emails contain links to fake resume download sites. A malicious Windows Shortcut file (LNK) is downloaded once the victim clicks on the link. This retrieves and executes a malicious DLL file, establishing persistence on the victim’s system, allowing the threat actors to maintain access. The malware collects sensitive information from the infected system. Additionally, it can download and execute supplementary malicious payloads.
Containment, Mitigations & Remediations
Remediation steps for addressing the More_eggs malware include:
- Disconnect infected systems from the network to prevent further spread
- Use reputable antivirus and anti-malware tools to detect and remove the malware
- Change all passwords and credentials that may have been compromised
- Apply all available security patches and updates to prevent future vulnerabilities
- Educate employees about phishing attacks and safe email practices.
Threat Landscape
The risk level to the recruitment sector from the More_eggs malware is likely to be high due to targeted phishing attacks, sensitive data exposure, operational disruptions, financial impact, and potential reputation damage.
The primary motivation behind More_eggs attacks is financial gain, through data theft, unauthorised transactions, and extortion. It primarily targets financial institutions, cryptocurrency entities, and corporate entities involved in financial operations.
The malware has a modular design, allowing it to adapt and evolve, making it a versatile and persistent threat. By using obfuscated code and complex infection chains, it can bypass traditional security measures and evade detection.
Threat Group
The More_eggs malware campaign is primarily attributed to the Venom Spider threat group. Emerging in 2018, it is known for its sophisticated cyber-attacks, particularly targeting HR departments with phishing emails disguised as job applications.
Venom Spider is financially motivated and operates under a MaaS model, allowing it to transcend geopolitical borders. It is known to operate globally, leveraging online platforms like LinkedIn to reach its targets.
The group is considered dangerous due its sophisticated cyber-attacks and the use of advanced malware like More_eggs. It poses significant risks to organisations with phishing emails, harvesting sensitive data, and deploying additional malicious payloads.
Further Information













