More_eggs

MITRE ATT&CK: S0284 View on attack.mitre.org

Aliases: SKID, Terra Loader, SpicyOmelette, More_eggs

First seen
2018-01-01 00:00:00
Malware type
backdoor, loader
Family
Malware family
Operating systems
windows
Related IoCs
13 (3 malicious)
Last IoC activity
2026-08-25 02:30:44
Profile updated
2026-07-07 12:40:21

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable "More_eggs" being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to More_eggs (S0284). The 3 most recently updated:

TypeIndicatorUpdatedSources
URL https://dcc.olcrv.com/login/tologin 2026-07-30 1
URL https://stevebrame.com 2026-07-20 1
URL https://dorseyinc.com 2025-02-28 1

Detection coverage

  • 253 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • File Deletion (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • Regsvr32 (attack-pattern)
  • System Owner/User Discovery (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2017-8759 (vulnerability)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • securityintelligence.com — More Eggs Anyone Threat Actor Itg08 Strikes Again (report)
  • proofpoint.com — Security Brief Ta4557 Targets Recruiters Directly Email (report)
  • proofpoint.com — Fake Jobs Campaigns Delivering Moreeggs Backdoor Fake Job Offers (report)
  • secureworks.com — Cybercriminals Increasingly Trying To Ensnare The Big Financial Fish (report)
  • Trend Micro — Cobalt Spam Runs Use Macros Cve 2017 8759 Exploit (report)
  • secureworks.com — Gold Kingswood (report)
  • ESET — More Evil Deep Look Evilnum Toolset (report)
  • blog.morphisec.com — Cobalt Gang 2.0 (report)
  • Cisco Talos — Multiple Cobalt Personality Disorder (report)
  • securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • mp.weixin.qq.com — Rexbtbni2Zxj4H3U6Ofmmw (report)
  • github.com — Evilnum (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.More Eggs (report)
  • twitter.com — 1301536930069278727 (report)
  • asert.arbornetworks.com — Double The Infection Double The Fun (report)
  • thehackernews.com — Moreeggs Malware Disguised As Resumes (report)
  • bitdefender.com — Bitdefender Whitepaper An Apt Blueprint Gaining New Visibility Into Financial Threats Interactive (report)
  • esentire.com — Unmasking Venom Spider (report)
  • expel.com — More Eggs And Some Linkedin Resume Spearphishing (report)
  • arcticwolf.com — Venom Spider Uses Server Side Polymorphism To Weave A Web Around Victims (report)
  • secureworks.com — Gold Kingswood (report)
  • quointelligence.eu — Golden Chickens Evolution Of The Maas (report)
  • MITRE ATT&CK — S0284 (report)

External references