more_eggs is a modular Windows malware associated with the Golden Chickens malware-as-a-service ecosystem, also tracked in connection with the operator commonly referred to as Venom Spider. It functions primarily as a stealthy backdoor and loader, enabling hands-on access to compromised systems and delivery of additional modules for follow-on intrusion activity. Known companion components in the broader ecosystem include VenomLNK for initial execution, TerraLoader for staging, TerraPreter for interactive access, TerraStealer for data theft, TerraTV for TeamViewer hijacking, and TerraCrypt for ransomware-related extortion activity. The malware has been used by financially motivated threat actors including FIN6, Evilnum, and Cobalt Group.
more_eggs is commonly delivered through highly targeted social-engineering campaigns, especially spearphishing themed around job offers, resumes, and hiring workflows. Observed lures have targeted both job seekers and corporate hiring managers, often using archive files containing disguised shortcut files and decoy documents. Infection chains have abused legitimate Windows utilities and script-driven execution, including regsvr32, msxsl, WMI, and in some campaigns ie4uinit, to load staged JavaScript or DLL components while reducing visibility.
On infected hosts, more_eggs and related loaders can collect host profiling data including username, IP address, and installed security products. It has been observed using encoded and encrypted command-and-control communications, including basE91 and RC4-based methods. The malware can decode and drop additional components, execute malicious DLLs through regsvr32, and remove itself from a system for cleanup. Its role as a loader and backdoor allows operators to deploy further payloads for credential theft, data theft, remote administration, and broader post-compromise operations.
The malware has been repeatedly linked to credential theft, particularly targeting corporate banking, email, and administrator accounts. In broader Golden Chickens operations, follow-on modules have supported exfiltration, lateral movement, and ransomware deployment. Victimology has centered on financially relevant organizations and enterprise users, including fintech, financial services, e-commerce, legal, staffing, healthcare technology, aerospace and defense, and other corporate environments where access to credentials or payment-related data is valuable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
VenomKit We use this name to describe documents generated by a builder purchased from the same seller as Taurus builder. Depending on the variant it may exploit CVE-2017-0199, CVE-2017-8570, CVE-2017-8759, CVE-2017-11882, CVE-2018-0802, and/or CVE-2018-8174.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Some of the malicious payloads leveraged as part of the attack campaign observed appear to be related to the More_eggs malicious payloads reported earlier... Based on what we observed as part of the OCX#HARVESTER attack campaign, it’s apparent that even recently, the More_eggs suite of malware used as part of the attack campaign is continually being maintained and retooled...
Among the tools used by the Evilnum group are More_eggs, TerraPreter, TerraStealer, and TerraTV.
Some of the malicious payloads leveraged as part of the attack campaign observed appear to be related to the More_eggs malicious payloads reported earlier... Based on what we observed as part of the OCX#HARVESTER attack campaign, it’s apparent that even recently, the More_eggs suite of malware used as part of the attack campaign is continually being maintained and retooled...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
As with most external attacks, phishing emails containing a malicious compressed zip file appears to be the primary delivery method.
The email attachment file analyzed by our team (screenshots-9201.jpg.zip) contains two shortcut files “ Screenshot-9501.JPG.lnk ” and “ Screenshot-9502.JPG.lnk ” disguised as jpeg.
The operators then send a link leading to a mock resume PDF through the organization‘s recruitment platform (e.g. Indeed, LinkedIn, or the organization‘s own career web page). The PDF purports to be broken, offering an embedded link to the malicious VenomLNK file on the branding website.
Defense Evasion T1027 Obfuscated Files or Information More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
This is done by using a common LOLbin technique which leverages the Windows binary file Ie4uinit.exe.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
115 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
90 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A maintained malware suite/MaaS used in phishing-led intrusions. In this campaign it uses obfuscated LNK, JavaScript loaders, LOLBins such as ie4uinit.exe and msxsl.exe, persistence via UserInitMprLogonScript, C2 communications, and follow-on payload delivery.
A malware family associated with Golden Chickens and used by other cybercrime groups including Cobalt Group, Evilnum, and FIN6.
A backdoor used in social-media spearphishing campaigns, delivered via malicious resumes/ZIPs to provide remote access/control of victim systems.
A malware suite observed using obfuscated batch/command content in .lnk-based execution chains; shown using variable substitution to construct C2 URLs and commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.