Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware

The Hacker News by The Hacker News
June 10, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jun 10, 2025Ravie LakshmananPhishing / Cybercrime

The financially motivated threat actor known as FIN6 has been observed leveraging fake resumes hosted on Amazon Web Services (AWS) infrastructure to deliver a malware family called More_eggs.

“By posing as job seekers and initiating conversations through platforms like LinkedIn and Indeed, the group builds rapport with recruiters before delivering phishing messages that lead to malware,” the DomainTools Investigations (DTI) team said in a report shared with The Hacker News.

More_eggs is the work of another cybercrime group called Golden Chickens (aka Venom Spider), which was most recently attributed to new malware families like TerraStealerV2 and TerraLogger. A JavaScript-based backdoor, it’s capable of enabling credential theft, system access, and follow-on attacks, including ransomware.

One of the malware’s known customers is FIN6 (aka Camouflage Tempest, Gold Franklin, ITG08, Skeleton Spider, and TA4557), an e-crime crew that originally targeted point-of-sale (PoS) systems in the hospitality and retail sectors to steal payment card details and profit off them. It’s operational since 2012.

Cybersecurity

The hacking group also has a history of using Magecart JavaScript skimmers to target e-commerce sites to harvest financial information.

According to payment card services company Visa, FIN6 has leveraged More_eggs as a first-stage payload as far back as 2018 to infiltrate several e-commerce merchants and inject malicious JavaScript code into the checkout pages with the ultimate goal of stealing card data.

“Stolen payment card data is later monetized by the group, sold to intermediaries, or sold openly on marketplaces such as JokerStash, prior to it shutting down in early 2021,” Secureworks notes in a profile of the threat actor.

The latest activity from FIN6 involves the use of social engineering to initiate contact with recruiters on professional job platforms like LinkedIn and Indeed, posing as job seekers to distribute a link (e.g., bobbyweisman[.]com, ryanberardi[.]com) that purports to host their resume.

DomainTools said the bogus domains, which masquerade as personal portfolios, are registered anonymously through GoDaddy for an extra layer of obfuscation that makes attribution and takedown efforts more difficult.

“By exploiting GoDaddy’s domain privacy services, FIN6 further shields the true registrant details from public view and takedown team,” the company said. “Although GoDaddy is a reputable and widely used domain registrar, its built-in privacy features make it easy for threat actors to hide their identities.”

Another noteworthy aspect is the use of trusted cloud services, such as AWS Elastic Compute Cloud (EC2) or S3, to host phishing sites. What’s more, the sites come with built-in traffic filtering logic to ensure that only prospective victims are served a link to download the supposed resume after completing a CAPTCHA check.

Cybersecurity

“Only users appearing to be on residential IP addresses and using common Windows-based browsers are allowed to download the malicious document,” DomainTools said. “If the visitor originates from a known VPN service, cloud infrastructure like AWS, or corporate security scanners, the site instead delivers a harmless plain-text version of the resume.”

The downloaded resume takes the form of a ZIP archive that, when opened, triggers an infection sequence to deploy the More_eggs malware.

“FIN6’s Skeleton Spider campaign shows how effective low-complexity phishing campaigns can be when paired with cloud infrastructure and advanced evasion,” the researchers concluded. “By using realistic job lures, bypassing scanners, and hiding malware behind CAPTCHA walls, they stay ahead of many detection tools.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Info-Tech Research Group Launches IT Playbooks Research Center to Solve IT Performance Gaps

Info-Tech Research Group Launches IT Playbooks Research Center to Solve IT Performance Gaps

Recommended.

IT Sustainability Think Tank: Perspectives on the print industry’s net-zero push in 2025 | Computer Weekly

IT Sustainability Think Tank: Perspectives on the print industry’s net-zero push in 2025 | Computer Weekly

December 15, 2025
Next big push in ETF industry? Why these risk assets are gaining traction as interest rate uncertainty persists

Next big push in ETF industry? Why these risk assets are gaining traction as interest rate uncertainty persists

August 8, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio