Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Strategies for next-gen medical technologies

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

FBI and Europol seize LeakBase forum used to trade stolen credentials

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn
Identity

Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn

userBy userJune 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 10, 2025Ravi LakshmananPhishing/Cybercrime

It has been observed that a financially motivated threat actor known as FIN6 leverages fake resumes hosted on Amazon Web Services (AWS) infrastructure to provide a malware family called More_eggs.

“By launching conversations through platforms such as LinkedIn, under the guise of job seekers, the group actually builds relationships with recruiters before delivering phishing messages that lead to malware,” the Domaintools Investigations (DTI) team said in a report shared with Hacker News.

More_eggs is a work by another cybercrime group called Golden Chickens (aka Venom Spider), which has recently been attributed to a new family of malware such as Terrastealerv2 and Terralogger. JavaScript-based backdoors can enable subsequent attacks that include credentials, system access, and ransomware.

One known customer for malware is FIN6 (aka Camouflage Tempest, Gold Franklin, ITG08, Skeleton Spider, and TA4557). It has been operational since 2012.

Cybersecurity

Hacking groups also have a history of using MageCart JavaScript skimmers to target e-commerce sites to collect financial information.

According to Payment Card Services Company Visa, FIN6 has used More_eggs as a first-stage payload until 2018 to infiltrate several e-commerce merchants, inserting malicious JavaScript code into the checkout page to set the ultimate goal of stealing card data.

“The data from the stolen payment cards will later be monetized by the group, sold to intermediaries, and openly sold in markets such as JokerStash before shutting down in early 2021,” SecureWorks said in the profile of threat actors.

FIN6’s latest activities include using social engineering to initiate contact with recruiters on professional job platforms such as LinkedIn, and posing as a job seeker who actually distributes links (for example, Bobbyweisman[.]com, ryanberardi[.]com) It is intended to host a resume.

Domaintoools said fake domains disguised as individual portfolios have been registered anonymously through adaddy and anonymously due to the extra layer of obfuscation that makes attributes and takedown efforts more difficult.

“By taking advantage of GoDaddy’s domain privacy services, Fin6 further protects true subscriber details from the public view and takedown team,” the company said. “GoDaddy is a well-reputed and widely used domain registrar, but its built-in privacy features allow threat actors to easily hide their identity.”

Another notable aspect is to use trusted cloud services such as AWS Elastic Compute Cloud (EC2) and S3 to host phishing sites. Additionally, the site comes with built-in traffic filtering logic so that only future victims will be provided with a link to download the expected resume after completing the CAPTCHA check.

Cybersecurity

“Only users who appear to be on a home IP address can download malicious documents using a typical Windows-based browser,” Domaintools said. “If the visitor comes from a known VPN service, a cloud infrastructure such as AWS, or a corporate security scanner, this site will instead provide a harmless, plain text version of your resume.”

The downloaded resume takes the form of a ZIP archive that triggers an infection sequence when opened to deploy the More_Eggs malware.

“FIN6’s skeleton spider campaign demonstrates how effective a low-complexity phishing campaign is when combined with cloud infrastructure and advanced evasion,” the researchers concluded. “We’re ahead of many detection tools by using realistic job lures, bypassing the scanner and hiding the malware behind the walls of the capture.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEnterprise Search Startup Green valuates $7.2 billion in Series F funding for $150 million
Next Article Michigan settles for $30 million with three survivors of the 2023 massive shooting
user
  • Website

Related Posts

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

March 5, 2026

FBI and Europol seize LeakBase forum used to trade stolen credentials

March 5, 2026

149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

March 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Strategies for next-gen medical technologies

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

FBI and Europol seize LeakBase forum used to trade stolen credentials

Anthropic CEO Dario Amodei calls OpenAI’s message about military agreement a ‘blatant lie,’ report says

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.