Cracking the Shell of More_eggs: Cyber Risks for SMBs & How MSPs Can Respond

Digital illustration showing a Guardz Threat Report cover with a shield bearing a G emblem. The background features binary code, emphasizing cybersecurity themes and the importance of SMBs in Cookie Theft Defense.

Key takeaways

  • More_eggs targets SMBs through stealth: More_eggs is a backdoor malware linked to the Golden Chickens MaaS framework. It enables follow-on attacks including data theft, ransomware, and cryptojacking.
  • SMBs face elevated risk: Limited cybersecurity awareness, operational disruption, data exposure, and the malware’s persistence make SMBs especially vulnerable.
  • MSPs should strengthen core defenses: Recommended measures include employee awareness training, phishing simulations, endpoint protection, email security, and incident response planning.
  • Unified security improves protection: Unified security platforms, browser protections, and AI-powered solutions help MSPs detect and mitigate evolving threats.

The cybersecurity world is no stranger to evolving threats, but the resurgence of the More_eggs malware campaign has captured fresh attention. In December 2024, a report revealed new iterations of this malware, highlighting its enhanced evasion techniques and tailored attack chains. For SMBs and the MSPs safeguarding them, this is a clarion call to reevaluate their cybersecurity strategies.

What Is More_eggs?

More_eggs is a backdoor malware associated with the Golden Chickens malware-as-a-service (MaaS) framework. It is used by cybercriminals to infiltrate networks, enabling follow-up attacks like data theft, ransomware, and cryptojacking.

Chain of Attack

Still have questions before choosing a plan?
Talk to a real human. No forms. No waiting. No Slack account needed.

No Slack account needed.

Campaign 1: VenomLNK → RevC2

  1. VenomLNK: An LNK file contains an obfuscated BAT script that downloads a decoy PNG file (API documentation) from a remote server.
  2. RevC2: An info-stealing backdoor communicates with a C&C server using WebSockets. It can steal passwords, execute commands, and capture screenshots.

Campaign 2: VenomLNK → Venom Loader → Retdoor

  1. VenomLNK: Writes VBS and BAT scripts to the Windows temporary directory. The VBS script triggers the BAT script to download a decoy cryptocurrency image and a malicious base.zip file from a remote server.
  2. Venom Loader: A custom-made loader decodes and delivers the Retdoor backdoor via PS1 scripts.
  3. Retdoor: Sends continuous HTTP POST requests to the C&C server with system details, executes encoded commands, and hides under system processes like “GoogleUpdate.”

Breaking Down the Terminology

Backdoor:
A backdoor is a type of malware that bypasses standard authentication methods to gain unauthorized access to a system. This allows attackers to remotely control resources like databases and file servers. With this access, they can execute system commands, steal sensitive data, or install additional malware undetected.

Loader:
A loader is a malicious tool designed to infiltrate devices and deliver harmful software (payloads). Once inside a system, loaders can gather system information, install other types of malware such as trojans or data stealers, and prepare the environment for further attacks.

These tools allow attackers to bypass conventional defenses, making them especially dangerous for SMBs with limited resources.

The Devastating Impact to Small Businesses

  1. Low Security Awareness:
    SMBs often lack dedicated IT teams and cybersecurity expertise. Employees may unknowingly click malicious links or open infected attachments, triggering the malware long before anyone knows what is happening.
  2. Financial and Operational Fallout:
    • Data Exposure: Breaches can result in regulatory fines and loss of customer trust.
    • Operational Disruption: Ransomware and data theft can paralyze critical business functions.
    • Reputational Damage: A compromised reputation can lead to client attrition.
  3. Stealth and Persistence:
    More_eggs thrives on its ability to evade detection, establishing long-term persistence and enabling subsequent attacks.  

MSP’s Role in Defending SMBs

MSPs are pivotal in addressing these challenges, serving as the first line of defense for SMBs. Here’s how they can combat threats like More_eggs:

1. Enhance Employee Awareness

  • Recurring Training: Use interactive videos and quizzes to teach employees how to spot phishing attempts and malicious files.
  • Phishing Simulations: Conduct periodic tests to evaluate and improve employee vigilance.

2. Deploy Advanced Endpoint Security

Endpoint protection solutions ensure continuous monitoring of all devices, especially crucial in hybrid or remote work environments. EDR tools with advanced NGAV capabilities are most effective at blocking this family of malware

3. Strengthen Email Security

Email remains a leading attack vector, with 90% of attacks originating from Phishing email. MSPs should deploy tools that scan attachments and URLs, proactively preventing threats like phishing and spoofing.

4. Implement Incident Response Plans

Regularly back up data and prepare a clear response plan to minimize downtime and financial loss in the event of an attack.

Proactive Measures for SMBs and MSPs

  • Unified Security Platforms: Tools that integrate Microsoft 365, Google Workspace, and endpoint protection enable MSPs to deliver holistic security.
  • Browser Protections: Real-time detection of malicious sites and phishing attempts can significantly reduce risk.
  • AI-Powered Solutions: Automation and predictive analytics allow MSPs to anticipate and mitigate evolving threats.

The Final Word

The More_eggs campaign underscores the urgent need for proactive cybersecurity. SMBs are particularly vulnerable, but MSPs armed with the right tools and strategies can make a decisive difference.

Solutions like Guardz not only protect against advanced threats but also simplify the complex security landscape for SMBs. Want to learn more? Visit Guardz.com today.

Categories:

Frequently Asked Questions

More_eggs is a backdoor malware that quietly establishes unauthorized access, allowing attackers to steal data, deploy ransomware, install additional malware, and maintain long-term persistence before organizations realize they have been compromised.

  • Train employees to recognize malicious attachments, links, and disguised shortcut (LNK) files.
  • Treat suspicious downloads and unexpected scripts as potential indicators of compromise.
  • Assume an initial infection may lead to multiple follow-on attacks rather than a single malware event.
  • Prioritize early detection to stop attackers before persistence is established.

Learn more about malware fundamentals.

Loaders deliver and execute additional malicious payloads, while backdoors provide persistent remote access that enables attackers to expand their operations over time.

  • Monitor for unexpected scripting activity such as PowerShell, BAT, and VBS execution.
  • Investigate processes that imitate legitimate applications to hide malicious activity.
  • Detect unusual outbound communications to command-and-control infrastructure.
  • Correlate endpoint telemetry with network activity to uncover multi-stage attacks.

Read our guide for related endpoint detection strategies.

The greatest opportunity for defense is identifying the early stages of the attack chain before attackers establish persistence and deploy secondary payloads.

  • Inspect suspicious email attachments and downloaded shortcut files.
  • Continuously monitor endpoints for abnormal script execution.
  • Deploy advanced endpoint detection and response (EDR) with modern prevention capabilities.
  • Prepare incident response procedures so compromised systems can be isolated immediately.

Explore ransomware response best practices in the first 24 hours after a data breach.

Guardz brings together email, endpoint, browser, and cloud security into a unified platform, helping MSPs detect and disrupt sophisticated attack chains before they escalate.

  • Protect Microsoft 365, Google Workspace, and managed endpoints through a unified approach.
  • Detect phishing attempts and malicious websites that commonly initiate malware infections.
  • Use AI-powered automation to identify suspicious activity earlier.
  • Simplify security operations by consolidating multiple protection layers.

Learn more about Guardz’s unified cybersecurity protection.

Sophisticated malware rarely targets a single security layer, making unified visibility across identities, email, endpoints, and browsers essential for detecting the complete attack chain.

  • Correlate alerts across multiple security controls instead of reviewing isolated events.
  • Reduce operational complexity by managing protections from one platform.
  • Identify attack progression earlier through centralized threat visibility.
  • Deliver stronger security outcomes while minimizing administrative overhead for MSPs.

Check our guide to learn more about AI-powered security for MSPs.

Subscribe to
Our Newsletter.

Abstract image of two overlapping shield shapes, one dark blue and one green, with a soft glowing effect on a light background—perfect for enhancing your single post template with a modern, secure aesthetic.
Abstract image with a large dark blue, semi-circular shape overlapping a bright green, glowing circular shape on a light gray background. Perfect for enhancing your single post template, the green circle appears partially blurred and luminous.

Keep your clients secure.

A stylized, dark blue shield icon with a green gradient glow on the right side, set against a light gray background—ideal for enhancing your single post template design.

Continue Reading

A hooded hacker attacks with digital code while a warrior inspired by Kratos defends with a shield, blocking access to credentials and security icons, symbolizing cybersecurity defense in a game-like battle.

Inside Kratos PhaaS

How MSPs Monitor Security Across Multiple Client Tenants

Green digital code streams down a black screen, resembling the iconic Matrix movie effect, with various symbols, letters, and numbers appearing in vertical columns—evoking the intricate workflows of MSPs managing cybersecurity in a multi-tenant model.

Cynet Alternatives for MSPs: 6 Platforms That Actually Fit the Multi-Tenant Model

A person in a futuristic chair sits at a high-tech control panel, looking out at a starry space scene with planets and mountains. The dashboard glows with colorful buttons and screens, like the perfect single post template for exploring new worlds.

Guardz, Your Cybersecurity
Co-Pilot for MSPs

Demonstrate the value you bring to the table as an MSP and gain visibility into your clients’ external postures.

Holistic Protection.
Hassle-Free.
Cost-Effective.
Slack
Slack
Chat with us No Slack account needed.