logo

Sinister "More_eggs" Malware Cracks Into Companies by Targeting Hiring Managers

ID: 423ac4c4-2464-5b27-a316-4c12aa15fb92

STIX ID: report--423ac4c4-2464-5b27-a316-4c12aa15fb92

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Researchers observed a LinkedIn-based phishing campaign that lures recruiters to fake resume sites which, when a purported resume is downloaded, deploy a Windows shortcut payload that silently installs the More_eggs modular backdoor. The More_eggs malware provides remote access, data-harvesting and secondary payload delivery capabilities; operators (reported as criminal MaaS groups like Golden Chickens) use social engineering and site-behavior changes to erase traces and increase infection success, highlighting the need for security training and recruitment-handling policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.