MORE_EGGS and some LinkedIn resumé spearphishing
ID: 432031b3-e424-53dd-9037-1e918f49e3b4
STIX ID: report--432031b3-e424-53dd-9037-1e918f49e3b4
Feed Name: Expel Blog
Threat Score
Expel SOC investigated a LinkedIn resume spearphish that redirected victims to a malicious PDF and decoy Word document which deployed a MORE_EGGS backdoor via fileless techniques (ie4uinit/msxsl/regsvr32, obfuscated JScript). The report reconstructs the execution timeline, identifies C2 domains and discovery activity, notes likely financially motivated threat actor linkages (e.g., FIN6/copycats), documents containment and remediation steps, and provides defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
