Security firms reported multiple spearphishing campaigns that used LinkedIn job applications, fake job offers, and poisoned resumes to deliver the More_eggs malware to recruiters, hiring managers, and other business professionals. In observed intrusions, victims were directed through legitimate-looking resume workflows that ended with a malicious archive or shortcut file, often disguised as a document, which launched obfuscated activity and installed the JavaScript-based backdoor. The campaigns were seen across sectors including industrial services, aerospace and defense, legal, accounting, staffing, and healthcare technology, showing a sustained focus on personnel involved in recruiting and hiring.
The malware and delivery chain were linked to Golden Chickens (also known as Venom Spider) and associated tooling such as VenomLNK, TerraLoader, and TerraPreter, though the specific operators behind individual incidents were not always confirmed. The attacks abused signed Windows binaries including regsvr32, wmic, msxsl.exe, ie4uinit.exe, and in earlier cases cmstp to evade detection, establish execution, perform discovery, and communicate with command-and-control infrastructure. Defenders said More_eggs can support credential theft, data exfiltration, lateral movement, remote access, and follow-on ransomware activity, and in at least one case endpoint telemetry caught suspicious XSL script processing and related malicious behavior before the intrusion succeeded.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
eSentire disclosed an unsuccessful phishing attack in May 2024 against an unnamed industrial services company, where a recruiter was lured by a fake applicant and resume download site. The malicious LNK retrieved a DLL via ie4uinit.exe, executed it with regsvr32.exe, established persistence, performed host discovery, and dropped the JavaScript-based More_eggs backdoor.
eSentire reported observing Golden Chickens campaigns using fake job offers and fake resumes between April 2021 and April 2022. The activity delivered the more_eggs malware suite through recruitment-themed lures targeting corporate employees and hiring managers.
Trend Micro reported that skimming activity began on Volusion's e-commerce cloud platform on September 7, 2019, after attackers injected malicious code into a Volusion JavaScript library used on checkout pages. The compromise affected 3,126 online shops and was attributed to Magecart Group 6, also known as FIN6.
eSentire said a February 2019 campaign targeted U.S. retail, entertainment, and pharmaceutical companies with fake job offers delivering the more_eggs malware. The report cited this as earlier precedent for later LinkedIn and resume-themed activity.
Proofpoint said it had tracked a series of fake job campaigns since mid-2018 that used LinkedIn outreach, follow-up emails, spoofed staffing-company sites, and malicious documents or loaders to deliver the More_eggs backdoor to primarily U.S. companies. The campaigns targeted sectors including retail, entertainment, pharmacy, and other businesses involved in online payments.
Expel observed a recruiter click a legitimate-looking LinkedIn resume workflow that led to a fake PDF error page, a ZIP masquerading as a .docx file, and a malicious LNK. The intrusion abused regsvr32, wmic, ie4uinit.exe, and msxsl.exe, triggered multiple Microsoft Defender for Endpoint alerts, and led to attempted command-and-control and data exfiltration before containment.
eSentire disclosed a campaign targeting hiring managers at four organizations: a U.S. aerospace/defense company, a large UK CPA firm, a Canada-based international business law firm, and a Canadian staffing agency. The campaign used fake resumes with a benign PDF decoy and a variant that abused ie4uinit.exe and msxsl.exe.
eSentire said three of four related more_eggs incidents in a renewed poisoned-resume campaign occurred at the end of March. The activity involved attackers posing as job applicants and sending fake resumes to hiring managers.
eSentire reported a spearphishing incident in which a healthcare-technology professional was targeted on LinkedIn with a fake job offer tailored to the victim's job title. The infection chain used VenomLNK, TerraLoader, TerraPreter, and abused WMI, cmstp, regsvr32, and msxsl before eSentire disrupted the attack.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 90 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
14 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityintelligence.com
Open sourceexpel.com
Open sourceesentire.com
Open sourceblog.talosintelligence.com
Open sourceattack.mitre.org
Open sourcewelivesecurity.com
Open sourceusa.visa.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.