By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware
Computing

FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware

News Room
Last updated: 2025/06/10 at 2:17 PM
News Room Published 10 June 2025
Share
SHARE

Jun 10, 2025Ravie LakshmananPhishing / Cybercrime

The financially motivated threat actor known as FIN6 has been observed leveraging fake resumes hosted on Amazon Web Services (AWS) infrastructure to deliver a malware family called More_eggs.

“By posing as job seekers and initiating conversations through platforms like LinkedIn and Indeed, the group builds rapport with recruiters before delivering phishing messages that lead to malware,” the DomainTools Investigations (DTI) team said in a report shared with The Hacker News.

More_eggs is the work of another cybercrime group called Golden Chickens (aka Venom Spider), which was most recently attributed to new malware families like TerraStealerV2 and TerraLogger. A JavaScript-based backdoor, it’s capable of enabling credential theft, system access, and follow-on attacks, including ransomware.

One of the malware’s known customers is FIN6 (aka Camouflage Tempest, Gold Franklin, ITG08, Skeleton Spider, and TA4557), an e-crime crew that originally targeted point-of-sale (PoS) systems in the hospitality and retail sectors to steal payment card details and profit off them. It’s operational since 2012.

Cybersecurity

The hacking group also has a history of using Magecart JavaScript skimmers to target e-commerce sites to harvest financial information.

According to payment card services company Visa, FIN6 has leveraged More_eggs as a first-stage payload as far back as 2018 to infiltrate several e-commerce merchants and inject malicious JavaScript code into the checkout pages with the ultimate goal of stealing card data.

“Stolen payment card data is later monetized by the group, sold to intermediaries, or sold openly on marketplaces such as JokerStash, prior to it shutting down in early 2021,” Secureworks notes in a profile of the threat actor.

The latest activity from FIN6 involves the use of social engineering to initiate contact with recruiters on professional job platforms like LinkedIn and Indeed, posing as job seekers to distribute a link (e.g., bobbyweisman[.]com, ryanberardi[.]com) that purports to host their resume.

DomainTools said the bogus domains, which masquerade as personal portfolios, are registered anonymously through GoDaddy for an extra layer of obfuscation that makes attribution and takedown efforts more difficult.

“By exploiting GoDaddy’s domain privacy services, FIN6 further shields the true registrant details from public view and takedown team,” the company said. “Although GoDaddy is a reputable and widely used domain registrar, its built-in privacy features make it easy for threat actors to hide their identities.”

Another noteworthy aspect is the use of trusted cloud services, such as AWS Elastic Compute Cloud (EC2) or S3, to host phishing sites. What’s more, the sites come with built-in traffic filtering logic to ensure that only prospective victims are served a link to download the supposed resume after completing a CAPTCHA check.

Cybersecurity

“Only users appearing to be on residential IP addresses and using common Windows-based browsers are allowed to download the malicious document,” DomainTools said. “If the visitor originates from a known VPN service, cloud infrastructure like AWS, or corporate security scanners, the site instead delivers a harmless plain-text version of the resume.”

The downloaded resume takes the form of a ZIP archive that, when opened, triggers an infection sequence to deploy the More_eggs malware.

“FIN6’s Skeleton Spider campaign shows how effective low-complexity phishing campaigns can be when paired with cloud infrastructure and advanced evasion,” the researchers concluded. “By using realistic job lures, bypassing scanners, and hiding malware behind CAPTCHA walls, they stay ahead of many detection tools.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Wayve to trial self-driving vehicles in London through Uber partnership – UKTN
Next Article Best Printer 2025: Our top-reviewed printers ranked
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Cyber crooks can now plant FAKE contacts on phones pretending to be mum & dad
News
TikTok Launches a Talent Manager Portal for Creators |
Computing
Disney and NBC Universal take ‘copyright free-rider’ Midjourney to court over alleged plagiarism – News
News
AI for Fuel, Not for Media-Slides: Yevhen Zherdiev’s View
Gadget

You Might also Like

Computing

TikTok Launches a Talent Manager Portal for Creators |

2 Min Read
Computing

Frontend Burnout Is Real — And This New Paradigm Might Be the Cure | HackerNoon

15 Min Read
Computing

Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool

3 Min Read
Computing

Xpeng Motors prepares for ADAS available outside of China: CEO · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?