More_eggs

S0284

Malware.View on attack.mitre.org

About this malware

More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable "More_eggs" being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1016
System Network Configuration Discovery

More_eggs has the capability to gather the IP address from the victim's machine.

T1016.001
Internet Connection Discovery

More_eggs has used HTTP GET requests to check internet connectivity.

T1027.013
Encrypted/Encoded File

More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end.

T1033
System Owner/User Discovery

More_eggs has the capability to gather the username from the victim's machine.

T1059.003
Windows Command Shell

More_eggs has used cmd.exe for execution.

T1070.004
File Deletion

More_eggs can remove itself from a system.

T1071.001
Web Protocols

More_eggs uses HTTPS for C2.

T1082
System Information Discovery

More_eggs has the capability to gather the OS version and computer name.

T1105
Ingress Tool Transfer

More_eggs can download and launch additional payloads.

T1132.001
Standard Encoding

More_eggs has used basE91 encoding, along with encryption, for C2 communication.

T1140
Deobfuscate/Decode Files or Information

More_eggs will decode malware components that are then dropped to the system.

T1218.010
Regsvr32

More_eggs has used regsvr32.exe to execute the malicious DLL.

T1518.001
Security Software Discovery

More_eggs can obtain information on installed anti-malware programs.

T1553.002
Code Signing

More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell.

T1573.001
Symmetric Cryptography

More_eggs has used an RC4-based encryption method for its C2 communications.

Groups that use it3

Campaigns0

None recorded.

References2

  1. Security Intelligence More Eggs Aug 2019 Open source
    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.
  2. Talos Cobalt Group July 2018 Open source
    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.