Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Chinese companies linked to Silk Typhoons have filed more than 15 patents for Cyberspy Tool

How AI Supercharges Transformational Change for ALS Imagination

When microgrids begin to talk to each other

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn
Identity

Fin6 delivers More_Eggs malware using fake resumes on AWS hosts on LinkedIn

userBy userJune 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 10, 2025Ravi LakshmananPhishing/Cybercrime

It has been observed that a financially motivated threat actor known as FIN6 leverages fake resumes hosted on Amazon Web Services (AWS) infrastructure to provide a malware family called More_eggs.

“By launching conversations through platforms such as LinkedIn, under the guise of job seekers, the group actually builds relationships with recruiters before delivering phishing messages that lead to malware,” the Domaintools Investigations (DTI) team said in a report shared with Hacker News.

More_eggs is a work by another cybercrime group called Golden Chickens (aka Venom Spider), which has recently been attributed to a new family of malware such as Terrastealerv2 and Terralogger. JavaScript-based backdoors can enable subsequent attacks that include credentials, system access, and ransomware.

One known customer for malware is FIN6 (aka Camouflage Tempest, Gold Franklin, ITG08, Skeleton Spider, and TA4557). It has been operational since 2012.

Cybersecurity

Hacking groups also have a history of using MageCart JavaScript skimmers to target e-commerce sites to collect financial information.

According to Payment Card Services Company Visa, FIN6 has used More_eggs as a first-stage payload until 2018 to infiltrate several e-commerce merchants, inserting malicious JavaScript code into the checkout page to set the ultimate goal of stealing card data.

“The data from the stolen payment cards will later be monetized by the group, sold to intermediaries, and openly sold in markets such as JokerStash before shutting down in early 2021,” SecureWorks said in the profile of threat actors.

FIN6’s latest activities include using social engineering to initiate contact with recruiters on professional job platforms such as LinkedIn, and posing as a job seeker who actually distributes links (for example, Bobbyweisman[.]com, ryanberardi[.]com) It is intended to host a resume.

Domaintoools said fake domains disguised as individual portfolios have been registered anonymously through adaddy and anonymously due to the extra layer of obfuscation that makes attributes and takedown efforts more difficult.

“By taking advantage of GoDaddy’s domain privacy services, Fin6 further protects true subscriber details from the public view and takedown team,” the company said. “GoDaddy is a well-reputed and widely used domain registrar, but its built-in privacy features allow threat actors to easily hide their identity.”

Another notable aspect is to use trusted cloud services such as AWS Elastic Compute Cloud (EC2) and S3 to host phishing sites. Additionally, the site comes with built-in traffic filtering logic so that only future victims will be provided with a link to download the expected resume after completing the CAPTCHA check.

Cybersecurity

“Only users who appear to be on a home IP address can download malicious documents using a typical Windows-based browser,” Domaintools said. “If the visitor comes from a known VPN service, a cloud infrastructure such as AWS, or a corporate security scanner, this site will instead provide a harmless, plain text version of your resume.”

The downloaded resume takes the form of a ZIP archive that triggers an infection sequence when opened to deploy the More_Eggs malware.

“FIN6’s skeleton spider campaign demonstrates how effective a low-complexity phishing campaign is when combined with cloud infrastructure and advanced evasion,” the researchers concluded. “We’re ahead of many detection tools by using realistic job lures, bypassing the scanner and hiding the malware behind the walls of the capture.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEnterprise Search Startup Green valuates $7.2 billion in Series F funding for $150 million
Next Article Michigan settles for $30 million with three survivors of the 2023 massive shooting
user
  • Website

Related Posts

Chinese companies linked to Silk Typhoons have filed more than 15 patents for Cyberspy Tool

July 30, 2025

Google launches DBSC Open Beta in Chrome and increases patch transparency via Project Zero

July 30, 2025

Hackers exploit SAP vulnerabilities to deploy automatic color malware in violation of Linux systems

July 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Chinese companies linked to Silk Typhoons have filed more than 15 patents for Cyberspy Tool

How AI Supercharges Transformational Change for ALS Imagination

When microgrids begin to talk to each other

Google launches DBSC Open Beta in Chrome and increases patch transparency via Project Zero

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.