logo

MORE_EGGS and some LinkedIn resumé spearphishing

ID: 432031b3-e424-53dd-9037-1e918f49e3b4

STIX ID: report--432031b3-e424-53dd-9037-1e918f49e3b4

Feed Name: Expel Blog

Threat Score
72/100

Date Published: 2022-08-26

Date Updated: 2026-04-27

Author: Kyle Pellett; Andrew Jerry

...
...

Expel SOC investigated a LinkedIn resume spearphish that redirected victims to a malicious PDF and decoy Word document which deployed a MORE_EGGS backdoor via fileless techniques (ie4uinit/msxsl/regsvr32, obfuscated JScript). The report reconstructs the execution timeline, identifies C2 domains and discovery activity, notes likely financially motivated threat actor linkages (e.g., FIN6/copycats), documents containment and remediation steps, and provides defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.