FIN6 Leverages Fake LinkedIn Resumes & AWS to Spread More_eggs Malware

FIN6 is using fake resumes hosted on AWS to deliver More_eggs malware, targeting recruiters on LinkedIn.
The financially motivated cybercriminal group FIN6 is using fake resumes, hosted on Amazon Web Services (AWS), to deliver the More_eggs malware. They are targeting recruiters on platforms like LinkedIn and Indeed.
FIN6 initiates contact with recruiters, posing as job seekers, and then sends phishing messages containing links to what appears to be their resume. These links lead to malicious websites hosted on AWS.
The More_eggs malware, a JavaScript-based backdoor, is supplied by the Golden Chickens group. It allows for credential theft, system access, and further attacks like ransomware deployment. FIN6 has been using More_eggs since at least 2018 to steal payment card data from e-commerce sites by injecting malicious JavaScript code.


The fake resume websites are designed to evade detection. They use GoDaddy's privacy services to hide the domain registration details and filter traffic to only serve the malicious payload to likely victims. If the site detects a VPN, cloud infrastructure (like AWS), or security scanners, it delivers a harmless, plain-text version of the resume. The malicious resume is delivered as a ZIP archive, which, when opened, infects the system with More_eggs.
DomainTools researchers emphasize that this campaign highlights the effectiveness of combining simple phishing techniques with cloud infrastructure and advanced evasion tactics. By using realistic job lures and CAPTCHA walls, FIN6 successfully bypasses many security detection tools.
- Other (42)
- Ransomware (152)
- Events and News (27)
- Features (45)
- Security (481)
- Tips (79)
- Google (24)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (46)
- Malware Alerts (223)
- Cyber Attack (274)
- Data Backup (12)
- Data Breach (111)
- Phishing (160)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (16)
- Updates (4)
- Alert (71)
- Hacking (59)
- Social Media (8)
- vulnerability (63)
- Hacker (33)
- Spyware (11)
- Windows (7)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (6)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (8)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (13)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)