216.73.216.6

Eggs in a Cloudy Basket: Skeleton Spider's Trusted Cloud Malware Delivery

· Published 11/06/2025 09:28 · Modified 11/06/2025 10:21

Export JSON

Essential information

Published
11/06/2025 09:28
Modified
11/06/2025 10:21
Tags
2025-06-11 aws backdoor cloud infrastructure evasion techniques more_eggs phishing resume lures skeleton spider social engineering
Related entities
24 observables, 1 intrusion sets (apt), 23 techniques (mitre), 4 malware

Description

, also known as FIN6, is a financially motivated cybercrime group that has evolved from POS breaches to broader enterprise threats. They employ tactics, posing as job seekers on platforms like LinkedIn to deliver messages. Their preferred payload is , a JavaScript-based . The group uses trusted cloud services like to host malicious infrastructure, evading detection. Their emails impersonate job applicants, with domains mimicking real names. FIN6 employs sophisticated filtering techniques to ensure malware delivery only to intended targets. The malware, developed by Venom Spider, allows for command execution and credential theft. Defense strategies include cautious handling of resume links, blocking execution of suspicious files, and implementing EDR policies.

External references