FIN6__2019__More_eggs_Anyone_Threat_Actor_ITG08_Strikes_Again.pdf
ID: a375529b-7823-41f6-b04d-76644d14e4bd
STIX ID: report--a375529b-7823-41f6-b04d-76644d14e4bd
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2019-08-31
Last Modified Date: 2019-08-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
IBM X-Force IRIS documents an active financially motivated campaign by ITG08/FIN6 that uses spear-phishing job lures to deliver the More_eggs JScript backdoor (aka Terra Loader/SpicyOmelette), Metasploit/Meterpreter stagers, and a signed DLL reverse-shell to steal payment data and maintain persistence; the report provides detailed malware analysis, TTPs, IOCs (domains, IPs, SHA256 hashes), and mitigation recommendations.
