More_eggs is a JavaScript backdoor targeting Windows systems, associated with the Golden Chickens malware-as-a-service ecosystem and used by financially motivated threat actors including Cobalt Group and Evilnum. Also known as SpicyOmelette, it has been deployed in attacks against financial organizations, including financial technology companies. Distribution includes phishing emails containing malicious links disguised as PDF documents and malicious Excel documents that execute COM-DLL-Dropper through Excel 4.0 macros.
The backdoor supports remote command execution, script execution, downloading and running executables or DLLs, returning command output, and uninstalling itself. It collects host information including usernames, IP addresses, Windows version, system installation date, and whether the host is a server or desktop. It also identifies installed antimalware products and checks running processes against identifiers associated with security and analysis software. SpicyOmelette supports reconnaissance of payment systems, payment gateways, and ATM infrastructure within compromised environments.
More_eggs protects command-and-control communications using RC4-based encryption and Base91 encoding and decodes malware components before dropping them onto the system. Its deployment chain uses obfuscated JavaScript and legitimate Windows utilities, including regsvr32 and the Microsoft XML transformation utility, for execution and application-control bypass. COM-DLL-Dropper deployments establish persistence for the JavaScript loader through scheduled tasks or user-logon mechanisms. The backdoor enables operators to deploy additional payloads and conduct follow-on post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The JavaScript backdoor saved to disk by the new COM-DLL-Dropper has version 6.6.
Among the tools used by the Evilnum group are More_eggs, TerraPreter, TerraStealer, and TerraTV.
Some of the malicious payloads leveraged as part of the attack campaign observed appear to be related to the More_eggs malicious payloads reported earlier... Based on what we observed as part of the OCX#HARVESTER attack campaign, it’s apparent that even recently, the More_eggs suite of malware used as part of the attack campaign is continually being maintained and retooled...
More_eggs – This is the Golden Chickens‘ key component. More_eggs provides threat actors with a back door and a malware loader.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“Either of the CobInt files downloads the main library from the C2 server as an HTML file”; “exec: download and run file (.exe or .dll).”
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
122 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
95 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A maintained malware suite/MaaS used in phishing-led intrusions. In this campaign it uses obfuscated LNK, JavaScript loaders, LOLBins such as ie4uinit.exe and msxsl.exe, persistence via UserInitMprLogonScript, C2 communications, and follow-on payload delivery.
A malware family associated with Golden Chickens and used by other cybercrime groups including Cobalt Group, Evilnum, and FIN6.
A backdoor used in social-media spearphishing campaigns, delivered via malicious resumes/ZIPs to provide remote access/control of victim systems.
A malware suite observed using obfuscated batch/command content in .lnk-based execution chains; shown using variable substitution to construct C2 URLs and commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.