A new malware campaign that impersonates as legitimate staffing companies abuse messaging services to deliver More_eggs malware.
The campaign primarily targeted US companies that include retail, entertainment, pharmacy, and others that commonly employ online payments, such as online shopping portals.
Threat actors send direct message abusing Linkedin message service to the victim’s pretending to be from a staffing company offering employment.
Proofpoint researchers observed a number of campaigns since 2018, that abuses message service to offer fake jobs and follow-up email’s to deliver More_eggs malware.
Threat actors use to create a Linkedin profile targeting individuals in a certain company and send them invitations with a short message.
Following the message attackers will send an Email to target’s work address reminding about the invitation. The Email contains a direct link added within the body of Email or as a PDF attachment embedded with URL.
Upon clicking URL or opening the PDF it takes victims to a spoofed landing page that triggers the download of Microsoft Word file with malicious macros embedded. In some cases instead of Microsoft Word file, it is JScript loader.
The campaign was first spotted by Brian Krebs that targets specific anti-money laundering officers at credit unions.
Threat actors used number of tools to distribute the malware
Taurus Builder – Tool purchased from underground markets, used to create malicious word documents.
VenomKit – An exploit kit to maintain unauthorized access on compromised servers.
More_eggs – Downloaded malware that used to download additional payloads.
Threat actors continue to increase their sophistication methods to deliver malware using a variety of campaigns. Here you can see the complete list of IOCs.
Wannamine Malware Still Penetrate the Unpatched SMB Computers using NSA’s EternalBlue Exploit
New Xbash Malware Attack on Linux & Windows with Botnet, Ransomware & Coinminer Capabilities
A former employee of Dutch semiconductor firm ASML, identified as German A. (43), stands accused…
A severe vulnerability has been identified in the Apache Parquet Java library, specifically within its parquet-avro module.…
A critical security flaw has been discovered in Halo ITSM, an IT support management software widely…
Several of Australia’s largest superannuation funds have been targeted in a coordinated cyberattack, leading to…
In a significant update to the popular dynamic instrumentation toolkit Frida, developers have introduced powerful…
OpenVPN, a widely-used open-source virtual private network (VPN) software, has recently patched a security vulnerability…