A new spear-phishing is targeting recruiters with a JavaScript backdoor called More_eggs.

“ A convincing decoy tricked a recruiter into downloading and executing a malicious file disguised as a resume. This led to the infection of the system with the more_eggs backdoor ,” Trend Micro researchers said .
More_eggs, sold as malware-as-a-service (MaaS), is a malware that can steal credentials for online banking accounts, email accounts, and IT administrator accounts. It has been linked to the Golden Chickens (also known as Venom Spider) but has been used by many other groups such as FIN6 (also known as ITG08), Cobalt, and Evilnum.
See also: Zimperium: Mobile devices targeted by phishing attacks
According to Trend Micro, in the most recent attack, threat actors sent a spear-phishing email in a possible attempt to build a relationship of trust with the victim. The attack was observed in late August 2024, targeting a talent search executive working in the engineering sector.
“Shortly after, a recruiter downloaded a purported resume, John Cboins.zip, from a URL using Google Chrome,” the researchers said. “It was not determined where this user obtained the URL. However, it was clear from the activities of both users that they were looking for a sales engineer.”
The URL in question, johncboins[.]com, contains a “Download Resume” button to entice the victim to download a ZIP file containing the LNK file.
Opening the LNK file by double-clicking leads to the execution of obfuscated commands, which in turn lead to the execution of a malicious DLL. This DLL is responsible for installing the More_eggs backdoor via a launcher.
See also: Phishing platform iServer taken down by authorities
More_eggs first checks whether it is running with administrator or user privileges, then executes a series of commands to reconnoiter the compromised host. It then connects to a command and control (C2) server to download and execute secondary malware payloads.
Trend Micro said it observed another variant of the campaign that includes PowerShell and Visual Basic Script (VBS) components as part of the infection process.
“Attributing these attacks to a specific group is difficult, due to the nature of MaaS, which allows for the use of various components and attack from partners,” he said. “This makes it difficult to identify specific threat actors, as many groups may use the same toolkits and infrastructure provided by services like those offered by Golden Chickens.”
That said, there is a suspicion that the attack could have been the work of the FIN6, especially considering the tactics, techniques, and procedures (TTPs) used.
See also: SambaSpy Malware: Targets Italian users with phishing emails
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection from spear-phishing emails
Be wary of unexpected emails: If you receive an email from an unknown sender that asks for sensitive information or asks you to open or download a file, be cautious. Always verify the purported sender through a separate communication channel before responding.
Check URLs: Hover over any links in the email and check if they match the URL shown in the email body. If they don't match, it could be a sign of fraud.
Don't open attachments from unknown sources: Opening attachments from unknown senders can potentially infect computer with malware or ransomware. If you're unsure about an attachment, don't risk it.
Use multi-factor authentication: This adds an extra layer of security by requiring more than one password to access accounts and systems. It can prevent hackers from gaining access even if they have obtained login credentials through a spear-phishing attack.
Stay up to date on new threats: Stay up to date on the latest methods used in spear-phishing attacks and learn how to recognize them.
Use anti-phishing software: There are several anti-phishing tools available that can help detect and prevent these attacks. Consider using one for added protection.
Source: thehackernews.com
