216.73.216.6

MDR in Action: Preventing The More_eggs Backdoor From Hatching

· Published 01/10/2024 10:12 · Modified 01/10/2024 10:22

Export JSON

Essential information

Published
01/10/2024 10:12
Modified
01/10/2024 10:22
Tags
2024-10-01 backdoor golden chickens malware-as-a-service mdr more_eggs recruitment skid spear-phishing spicyomelette terra loader vision one
Related entities
10 observables, 1 intrusion sets (apt), 13 techniques (mitre), 4 malware, 4 others

Description

A sophisticated attack led to a infection at a company. The attack began with an email to a senior executive, followed by a officer downloading a fake resume. The malicious file, disguised as a resume, contained obfuscated commands that executed when opened. This resulted in the download and execution of the . The malware performed system checks and communicated with a command-and-control server. Trend Micro's team quickly identified and contained the threat using platform, isolating the infected host and blocking indicators. The incident is part of a broader campaign using the malware toolkit, with two variations observed targeting various industries, particularly those with financial resources.

External references