More_eggs Malware Disguised as Resumes Targets Recruiters in Phishing Attack
ID: bac0de97-aeb3-574b-bd5b-18e28369cc38
STIX ID: report--bac0de97-aeb3-574b-bd5b-18e28369cc38
Feed Name: The Hacker News
Security researchers reported active phishing campaigns: More_eggs backdoor deployments masquerading as resumes to target recruiters (using LNK files, ie4uinit.exe and regsvr32 for payload execution and persistence) linked to the Golden Chickens/Venom Spider group; a drive-by distribution of Vidar stealer via fake KMSPico sites; and the V3B phishing kit targeting EU banking customers to harvest credentials, OTPs and perform QRLJacking — all distributed via MaaS/PhaaS models and social-engineering techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
