Monday, November 25, 2024
HomeComputer SecurityHackers Abusing LinkedIn’s Direct Messaging Service to Deliver More_eggs Malware via Fake...

Hackers Abusing LinkedIn’s Direct Messaging Service to Deliver More_eggs Malware via Fake Job Offers

Published on

A new malware campaign that impersonates as legitimate staffing companies abuse messaging services to deliver More_eggs malware.

The campaign primarily targeted US companies that include retail, entertainment, pharmacy, and others that commonly employ online payments, such as online shopping portals.

Threat actors send direct message abusing Linkedin message service to the victim’s pretending to be from a staffing company offering employment.

- Advertisement - SIEM as a Service

Proofpoint researchers observed a number of campaigns since 2018, that abuses message service to offer fake jobs and follow-up email’s to deliver More_eggs malware.

More_eggs Malware Campaign

Threat actors use to create a Linkedin profile targeting individuals in a certain company and send them invitations with a short message.

More_eggs malware

Following the message attackers will send an Email to target’s work address reminding about the invitation. The Email contains a direct link added within the body of Email or as a PDF attachment embedded with URL.

Upon clicking URL or opening the PDF it takes victims to a spoofed landing page that triggers the download of Microsoft Word file with malicious macros embedded. In some cases instead of Microsoft Word file, it is JScript loader.

More_eggs malware

The campaign was first spotted by Brian Krebs that targets specific anti-money laundering officers at credit unions.

Threat actors used number of tools to distribute the malware

Taurus Builder – Tool purchased from underground markets, used to create malicious word documents.

VenomKit – An exploit kit to maintain unauthorized access on compromised servers.

More_eggs – Downloaded malware that used to download additional payloads.

Threat actors continue to increase their sophistication methods to deliver malware using a variety of campaigns. Here you can see the complete list of IOCs.

Related Read

Wannamine Malware Still Penetrate the Unpatched SMB Computers using NSA’s EternalBlue Exploit

New Xbash Malware Attack on Linux & Windows with Botnet, Ransomware & Coinminer Capabilities

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...