Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

Family File Suit Challenges Arkansas Law Requiring 10 Commandments to be posted in classrooms

The chime price IPO is $27 per share, valuing Fintech at $11.6 billion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn
Identity

Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn

userBy userJune 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 10, 2025Ravi LakshmananPhishing/Cybercrime

It has been observed that a financially motivated threat actor known as FIN6 leverages fake resumes hosted on Amazon Web Services (AWS) infrastructure to provide a malware family called More_eggs.

“By launching conversations through platforms such as LinkedIn, under the guise of job seekers, the group actually builds relationships with recruiters before delivering phishing messages that lead to malware,” the Domaintools Investigations (DTI) team said in a report shared with Hacker News.

More_eggs is a work by another cybercrime group called Golden Chickens (aka Venom Spider), which has recently been attributed to a new family of malware such as Terrastealerv2 and Terralogger. JavaScript-based backdoors can enable subsequent attacks that include credentials, system access, and ransomware.

One known customer for malware is FIN6 (aka Camouflage Tempest, Gold Franklin, ITG08, Skeleton Spider, and TA4557). It has been operational since 2012.

Cybersecurity

Hacking groups also have a history of using MageCart JavaScript skimmers to target e-commerce sites to collect financial information.

According to Payment Card Services Company Visa, FIN6 has used More_eggs as a first-stage payload until 2018 to infiltrate several e-commerce merchants, inserting malicious JavaScript code into the checkout page to set the ultimate goal of stealing card data.

“The data from the stolen payment cards will later be monetized by the group, sold to intermediaries, and openly sold in markets such as JokerStash before shutting down in early 2021,” SecureWorks said in the profile of threat actors.

FIN6’s latest activities include using social engineering to initiate contact with recruiters on professional job platforms such as LinkedIn, and posing as a job seeker who actually distributes links (for example, Bobbyweisman[.]com, ryanberardi[.]com) It is intended to host a resume.

Domaintoools said fake domains disguised as individual portfolios have been registered anonymously through adaddy and anonymously due to the extra layer of obfuscation that makes attributes and takedown efforts more difficult.

“By taking advantage of GoDaddy’s domain privacy services, Fin6 further protects true subscriber details from the public view and takedown team,” the company said. “GoDaddy is a well-reputed and widely used domain registrar, but its built-in privacy features allow threat actors to easily hide their identity.”

Another notable aspect is to use trusted cloud services such as AWS Elastic Compute Cloud (EC2) and S3 to host phishing sites. Additionally, the site comes with built-in traffic filtering logic so that only future victims will be provided with a link to download the expected resume after completing the CAPTCHA check.

Cybersecurity

“Only users who appear to be on a home IP address can download malicious documents using a typical Windows-based browser,” Domaintools said. “If the visitor comes from a known VPN service, a cloud infrastructure such as AWS, or a corporate security scanner, this site will instead provide a harmless, plain text version of your resume.”

The downloaded resume takes the form of a ZIP archive that triggers an infection sequence when opened to deploy the More_Eggs malware.

“FIN6’s skeleton spider campaign demonstrates how effective a low-complexity phishing campaign is when combined with cloud infrastructure and advanced evasion,” the researchers concluded. “We’re ahead of many detection tools by using realistic job lures, bypassing the scanner and hiding the malware behind the walls of the capture.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEnterprise Search Startup Green valuates $7.2 billion in Series F funding for $150 million
Next Article Michigan settles for $30 million with three survivors of the 2023 massive shooting
user
  • Website

Related Posts

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

June 12, 2025

Former Black Busta members use Microsoft team and Python scripts in the 2025 attack

June 11, 2025

295 Malicious IPS launches a coordinated brute force attack against ApacheTomcat manager

June 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

Family File Suit Challenges Arkansas Law Requiring 10 Commandments to be posted in classrooms

The chime price IPO is $27 per share, valuing Fintech at $11.6 billion

What is the most popular casino in the US?

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

What is the most popular casino in the US?

Top 10 Startup and Tech Funding News – June 11, 2025

Huawei launches Pura 80 series and challenges Apple in China’s premium phone market

Israeli AI AI Data Security Startup Cyera raises $540 million and doubles its valuation to $600 million in seven months

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.