Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security More_Eggs Backdoor
Cyber Security

More_Eggs Backdoor

← Back to Glossary
By NHI Mgmt Group Updated September 18, 2026 Domain: Cyber Security

A backdoor used by threat actors to maintain access after initial compromise. It can profile the endpoint, establish persistence, and deliver additional payloads. In practice, it often appears as part of a multi-stage intrusion chain that uses social engineering and system-native execution techniques to evade detection.

How the More_Eggs Backdoor Works

More_Eggs is not just a one-off implant, it is a post-compromise foothold designed to keep an intrusion alive. Its value to an attacker comes from persistence, endpoint profiling, and the ability to stage later payloads without having to repeat the initial access step.

That makes the backdoor a bridge between first access and full operational control. Once it is running, defenders should assume the attacker can observe the host, adapt follow-on tooling, and continue the intrusion chain while blending into normal system activity.

Because the malware often relies on social engineering and native execution, its behavior can resemble legitimate administrative or user-driven activity until deeper telemetry is reviewed.

Where It Fits in the Intrusion Chain

More_Eggs usually matters less as a standalone payload than as an enabler for the next phase of compromise. It is commonly used after a successful lure or execution event, then left in place so the operator can return, expand, or load additional tooling as needed.

This pattern is especially relevant in multi-stage intrusions, where one artifact is used to establish trust, another to persist, and a later payload to achieve the actual objective. That separation of roles makes attribution harder and response slower, because defenders may see only fragments of the full attack path.

System-native execution techniques increase the chance that execution looks routine, which helps the backdoor survive long enough to deliver its next stage.

Security Implications of a Persistent Backdoor

A persistent backdoor changes the security posture of the affected endpoint from a single incident to an ongoing compromise. The main concern is not only the original infection, but the attacker’s ability to return, pivot, and keep deploying new payloads after the first compromise is believed to be over.

That persistence also creates detection pressure. If endpoint profiling is successful, an operator can choose follow-on actions that fit the environment, making malicious activity look more contextual and less obviously anomalous.

For defenders, the practical implication is that removal must address the underlying persistence and execution path, not just the visible binary or process tree.

How Defenders Should Interpret It

When More_Eggs appears, treat it as evidence of an intrusion campaign that is still active or at least designed for re-entry. The backdoor’s role is to preserve attacker options, so a narrow cleanup that ignores companion persistence, staging, or adjacent credentials can leave the environment exposed.

Its use of social engineering and native execution also means security teams should correlate user execution paths, parent-child process chains, and post-infection outbound activity rather than relying on a single indicator.

In practice, the most important question is whether the endpoint has been fully cleared of the attacker’s control path, not whether the initial payload was removed.

Risk and Threat Considerations

Persistent backdoors are dangerous because they convert one successful intrusion into repeated access. If the implant can profile the host and load more tooling, the attacker can adapt their actions over time, which raises the likelihood of lateral movement, data theft, and prolonged dwell time.

Failure mechanism: Social engineering and system-native execution can bypass user suspicion and some endpoint controls, while persistence keeps the operator’s access alive after the initial entry point is discovered.

Impact: The compromised host can become a reusable launch point for additional payload delivery, further compromise, and continued attacker presence even after a partial response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1071 — Application Layer ProtocolBackdoor staging often rides routine protocol traffic to blend in.
T1059 — Command and Scripting InterpreterSystem-native execution is a common way backdoors execute payloads.
T1547 — Boot or Logon Autostart ExecutionPersistence is central to a backdoor that must survive re-entry.
Recommendation — Inspect outbound C2-like traffic and hunt for command channels masquerading as normal application protocols. Monitor script and shell execution paths for suspicious parent-child process chains. Review and remove autostart persistence mechanisms to break attacker re-access.
CIS Controls v88 — Audit Log ManagementBackdoor activity is best validated through endpoint and process telemetry.
10 — Malware DefensesBackdoors are malware that require detection and containment controls.
Recommendation — Centralize and correlate logs to reconstruct the intrusion chain and identify persistence. Use malware defenses to detect, quarantine, and block backdoor execution and follow-on payloads.
NIST CSF 2.0DE.CM — Continuous MonitoringA persistent backdoor creates ongoing monitoring demand on compromised hosts.
RS.AN — AnalysisIntrusion chains require analysis of how the backdoor established and maintained access.
Recommendation — Continuously monitor endpoints for persistence, staging activity, and suspicious execution patterns. Analyze the attack path to determine how initial access, persistence, and payload delivery were linked.

Practitioner Guidance

What to watch for: Focus on the execution chain around the backdoor, not just the file itself. A post-compromise implant that profiles the endpoint and stages later payloads usually means the environment has already been operationally penetrated.

Practitioner takeaway: Treat removal as a campaign response problem, because persistence, staging, and native execution often matter more than the initial delivery method.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org