Eggs in a Cloudy Basket: Skeleton Spider's Trusted Cloud Malware Delivery
June 11, 2025, 10:21 a.m.
Description
Skeleton Spider, also known as FIN6, is a financially motivated cybercrime group that has evolved from POS breaches to broader enterprise threats. They employ social engineering tactics, posing as job seekers on platforms like LinkedIn to deliver phishing messages. Their preferred payload is more_eggs, a JavaScript-based backdoor. The group uses trusted cloud services like AWS to host malicious infrastructure, evading detection. Their phishing emails impersonate job applicants, with domains mimicking real names. FIN6 employs sophisticated filtering techniques to ensure malware delivery only to intended targets. The more_eggs malware, developed by Venom Spider, allows for command execution and credential theft. Defense strategies include cautious handling of resume links, blocking execution of suspicious files, and implementing EDR policies.
Tags
Date
- Created: June 11, 2025, 9:28 a.m.
- Published: June 11, 2025, 9:28 a.m.
- Modified: June 11, 2025, 10:21 a.m.
Indicators
- c2c40859f5d589538b6c16d654373b696c48e0be9092b56a57d2cf6ce768e1fe
- 8b67eb5c3586b427fd71310c1a0e6c92c35497342afcc0533e5bd97b7b572185
- 9f940783a6bbeaca52308b32e7bc0060222f3705c2db2ab00f59c6615e5e577f
- 14e722855605ba78dc1d21153f0e1be90e7528149f2cd2d7d6eba8ef27534bdc
- 208.109.231.95
- https://tool.municipiodechepo.org/id/
- https://6f4922f4.bobbyweisman.com/brake/
- http://bobbyweisman.com/index.html
- http://bobbyweisman.com
- http://93f4f4.bobbyweisman.com/kakfgar
- ryanberardi.com
- malenebutler.com
- lorinash.com
- kimberlykamara.com
- emersonkelly.com
- edwarddhall.com
- davidlesnick.com
- bobbybradley.net
- annalanyi.com
- alanpower.net
- tool.municipiodechepo.org
- 93f4f4.bobbyweisman.com
- bobbyweisman.com
- 6f4922f4.bobbyweisman.com