The group is using the More_eggs JScript backdoor to anchor its attack.
Source: Threadpost