More_eggs
MITRE ATT&CK: S0284 View on attack.mitre.org
Aliases: SKID, Terra Loader, SpicyOmelette, More_eggs
- First seen
- 2018-01-01 00:00:00
- Malware type
- backdoor, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 13 (3 malicious)
- Last IoC activity
- 2026-08-25 02:30:44
- Profile updated
- 2026-07-07 12:40:21
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable "More_eggs" being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to More_eggs (S0284). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | https://dcc.olcrv.com/login/tologin | 2026-07-30 | 1 |
| URL | https://stevebrame.com | 2026-07-20 | 1 |
| URL | https://dorseyinc.com | 2025-02-28 | 1 |
Detection coverage
- 253 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Information Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Windows Command Shell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- File Deletion (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Security Software Discovery (attack-pattern)
- Code Signing (attack-pattern)
- Regsvr32 (attack-pattern)
- System Owner/User Discovery (attack-pattern)
Used by threat actors
- Cobalt Group (threat-actor)
- Evilnum (threat-actor)
- FIN6 (threat-actor)
Exploited vulnerabilities
- CVE-2017-8759 (vulnerability)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- securityintelligence.com — More Eggs Anyone Threat Actor Itg08 Strikes Again (report)
- proofpoint.com — Security Brief Ta4557 Targets Recruiters Directly Email (report)
- proofpoint.com — Fake Jobs Campaigns Delivering Moreeggs Backdoor Fake Job Offers (report)
- secureworks.com — Cybercriminals Increasingly Trying To Ensnare The Big Financial Fish (report)
- Trend Micro — Cobalt Spam Runs Use Macros Cve 2017 8759 Exploit (report)
- secureworks.com — Gold Kingswood (report)
- ESET — More Evil Deep Look Evilnum Toolset (report)
- blog.morphisec.com — Cobalt Gang 2.0 (report)
- Cisco Talos — Multiple Cobalt Personality Disorder (report)
- securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- mp.weixin.qq.com — Rexbtbni2Zxj4H3U6Ofmmw (report)
- github.com — Evilnum (report)
- malpedia.caad.fkie.fraunhofer.de — Js.More Eggs (report)
- twitter.com — 1301536930069278727 (report)
- asert.arbornetworks.com — Double The Infection Double The Fun (report)
- thehackernews.com — Moreeggs Malware Disguised As Resumes (report)
- bitdefender.com — Bitdefender Whitepaper An Apt Blueprint Gaining New Visibility Into Financial Threats Interactive (report)
- esentire.com — Unmasking Venom Spider (report)
- expel.com — More Eggs And Some Linkedin Resume Spearphishing (report)
- arcticwolf.com — Venom Spider Uses Server Side Polymorphism To Weave A Web Around Victims (report)
- secureworks.com — Gold Kingswood (report)
- quointelligence.eu — Golden Chickens Evolution Of The Maas (report)
- MITRE ATT&CK — S0284 (report)
External references
- mitre-attack — S0284
- SKID
- SpicyOmelette
- Terra Loader
- More_eggs
- Crowdstrike GTR2020 Mar 2020
- ESET EvilNum July 2020
- Talos Cobalt Group July 2018
- Security Intelligence More Eggs Aug 2019
- Visa FIN6 Feb 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy