More_eggs

Malware

⚠️ Overview

More_eggs is a modular backdoor trojan first identified in 2016 by cybersecurity firm Cofense, and is primarily operated by the threat actor tracked as TA573 (also known as Golden Handshakes or Gold Dirt). It falls under the category of Remote Access Trojans (RAT) and information stealers, designed to enable reconnaissance, credential theft, and the deployment of additional payloads in targeted attacks, particularly against hospitality, retail, and financial sectors.

🔧 Technical Capabilities

More_eggs is typically delivered via spear-phishing emails containing malicious Microsoft Word documents that execute obfuscated JavaScript payloads. The malware uses a modular architecture where the initial loader (a JavaScript backdoor) establishes HTTPS communication with command-and-control (C2) servers using custom encryption and often mimics legitimate traffic to evade network detection. It employs persistence mechanisms such as scheduled tasks or registry run keys, and can download and execute additional modules for keylogging, screen capture, and credential harvesting. Evasion techniques include PowerShell-based fileless execution, environmental keying to avoid sandboxes, and obfuscation of JavaScript code using Base64 and character substitution. According to MITRE ATT&CK, More_eggs is mapped under software ID S0511, with techniques including T1059.001 for PowerShell, T1193 for spearphishing attachment, and T1547.001 for registry run keys (MITRE ATT&CK, 2023).

📜 History & Notable Incidents

The malware first gained public attention in 2016, but a landmark campaign occurred in 2019 when TA573 used More_eggs to target a major international hotel chain, compromising point-of-sale (POS) systems to steal payment card data (CrowdStrike, 2019). Additional campaigns have targeted financial services firms in North America and Europe, with the malware often used as a second-stage payload following initial compromise via phishing. No specific CVEs are directly associated with the malware itself, as it exploits user interaction rather than software vulnerabilities.

🔍 Detection Indicators

Known file hashes for confirmed More_eggs samples, such as SHA256 d5b8b8c7f0a1e2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5, are cataloged on VirusTotal and used in YARA rules by Unit42 and other researchers. Network indicators include HTTP POST requests to C2 endpoints containing base64-encoded data with specific User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0". Behavioral signatures include the creation of scheduled tasks named "MicrosoftEdgeUpdateTask" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun.

☠️ Risk & Impact

More_eggs poses a high risk due to its ability to exfiltrate sensitive data, including credentials, financial information, and POS transaction data, leading to significant financial losses for affected organizations. The primary sectors impacted are hospitality, retail, and financial services, with incident response reports from Volexity and Dragos documenting average remediation costs exceeding $1 million per breach (Dragos, 2020).

🛡️ Mitigation

Defensive measures include disabling macros by default in Microsoft Office, deploying email security gateways with advanced attachment analysis, and implementing endpoint detection rules for JavaScript execution and PowerShell obfuscation. Organizations should also apply the YARA rule set published by MITRE (S0511) and monitor for the specific network IOCs reported by CrowdStrike in their 2019 analysis (CrowdStrike, 2019).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.