Recruiters, beware of cybercrooks posing as job applicants!

Recruiters are being targeted via spear-phishing emails sent by cybercrooks impersonating job applicants, Proofpoint researchers are warning.
The threat actor - designated as TA4557 by Proofpoint - first reaches out to recruiters with a spear-phishing email with no malicious link or attachment, just an inquiry into whether a job position at a company is still open.
This first email is meant to prime the recruiter to implicitly trust the link provided in the follow-up email, which points to a fake resume website.
The latter uses a CAPTCHA that, when completed, triggers the download of a ZIP file containing a shortcut file.
A scriptlet is downloaded and executed The scriptlet drops a DLL file in the %APPDATA%Microsoft folder and tries to execute it either via Windows Management Instrumentation or the ActiveX Object Run method.
The DLL retrieves a RC4 key, which it uses to decipher the More Eggs backdoor, and drops the backdoor and a MSXSL executable.
WMI is again used to create the MSXSL process, and the DLL deletes itself.
The backdoor, which can be used to profile the system, drop additional malicious payloads and establish persistence, is finally safely ensconced on the target machine.
The researchers say that they have seen an increase in threat actors using benign messages to build trust and engage with a target before sending the malicious content.
The threat actor is regularly changing their sender emails, fake resume domains, and infrastructure to prevent their emails to be flagged by email filters.


This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 12 Dec 2023 14:13:10 +0000


Cyber News related to Recruiters, beware of cybercrooks posing as job applicants!

Recruiters, beware of cybercrooks posing as job applicants! - Recruiters are being targeted via spear-phishing emails sent by cybercrooks impersonating job applicants, Proofpoint researchers are warning. The threat actor - designated as TA4557 by Proofpoint - first reaches out to recruiters with a ...
1 year ago Helpnetsecurity.com
Recruiters Beware! Hackers Deliver Malware Posing Job Applicant - Threat actors have been targeting recruiters disguised as job applicants to deliver their malware. Though this method is not unique, the technique and attack vectors have been noted to have changed from their previous methods. TA4557 is a highly ...
1 year ago Cybersecuritynews.com FIN6
Cybercrime Groups Offering Six-Figure Salaries for IT Talents - Increasingly, organized crime organizations are operating as businesses rather than criminal organizations, advertising jobs on the dark web with a number of advantages for members. A recent Kaspersky study found that 61% of job ads posted by hacking ...
2 years ago Cybersecuritynews.com
How to Protect Yourself from Job Scams: Essential Tips - The internet is a powerful tool in our career search, but it also provides cyber criminals with information and tactics they can use to exploit and deceive people looking for work. Job scams are sadly prevalent on the web, and if you’re job ...
2 years ago Tripwire.com
'123456' password exposed chats for 64 million McDonald’s job applicants - "During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an ...
4 months ago Bleepingcomputer.com
'123456' password exposed info for 64 million McDonald’s job applicants - "During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an ...
4 months ago Bleepingcomputer.com
Cybercrime Groups Offer Up to $20K/Month Jobs on the Dark Web - Cybercrime groups are increasingly running their operations as a business, promoting jobs on the dark web that offer developers and hackers competitive monthly salaries, paid time off, and paid sick leaves. In a new report by Kaspersky, which ...
2 years ago Bleepingcomputer.com
Attackers Targeting Recruiters With More_Eggs Backdoor - FIN6 has been known in the past to pose as recruitment officers to target job seekers, but it appears to be "moving from posing as fake recruiters to now masquerading as fake job applicants" in a shift in tactics, Trend Micro researchers ...
1 year ago Darkreading.com FIN6
Proofpoint Exposes Sophisticated Social Engineering Attack on Recruiters That Infects Their Computers With Malware - Recruiters and anyone else involved in hiring processes should be knowledgeable about this social engineering attack threat. A new report from U.S.-based cybersecurity company Proofpoint exposes a new attack campaign operated by a ...
1 year ago Techrepublic.com
'123456' password exposed chats for 64 million McDonald’s job applications - "During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an ...
4 months ago Bleepingcomputer.com
'123456' password exposed chats for 64 million McDonald’s job chatbot applications - "During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an ...
4 months ago Bleepingcomputer.com
Fake Recruiters Defraud Facebook Users via Remote Work Offers - A fresh wave of job scams is spreading on Meta's Facebook platform that aims to lure users with offers for remote-home positions and ultimately defraud them by stealing their personal data and banking credentials. The attackers dangle offers of ...
1 year ago Darkreading.com
Threat Actor Targets Recruiters With Malware - Proofpoint has warned recruiters of a skilled threat actor targeting them with emails designed to deploy malware. TA4557 is a financially motivated threat actor known to distribute the More Eggs backdoor, which is designed to establish persistence, ...
1 year ago Infosecurity-magazine.com FIN6
CVE-2025-21688 - In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Assign job pointer to NULL before signaling the fence In commit e4b5ccd392b9 ("drm/v3d: Ensure job pointer is set to NULL after job completion"), we introduced a change to ...
9 months ago Tenable.com
McDonald’s AI Hiring Bot With Password ‘123456’ Millions of Job-Seekers Data - Both McDonald’s and Paradox.ai acknowledged the severity of the breach, with McDonald’s expressing disappointment in their third-party provider’s security failures. The system’s backend infrastructure, developed by Paradox.ai, ...
4 months ago Cybersecuritynews.com
Squid Werewolf Mimic as Recruiters Attacking Job Seekers To Exfiltrate Personal Data - To protect against such threats, security experts recommend implementing email security solutions, avoiding opening attachments from unknown senders, and deploying endpoint detection and response tools capable of identifying suspicious PowerShell ...
8 months ago Cybersecuritynews.com APT37 APT3
Beware of Fake Job Interview Challenges Attacking Developers To Deliver Malware - The ultimate goal is to trick developers into executing trojanized codebases that deploy malware designed to steal cryptocurrency wallet data, browser credentials, and sensitive system information. The malware’s browser module targets Chrome, ...
9 months ago Cybersecuritynews.com
'ResumeLooters' Attackers Steal Millions of Career Records - Attackers used SQL injection and cross-site scripting to target at least 65 job-recruitment and retail websites with legitimate penetration-testing tools, stealing databases containing more than 2 million emails and other personal records of job ...
1 year ago Darkreading.com
Threat Actors With Fake Job Lures Attacking Job Seekers - Cybercriminals are increasingly exploiting job seekers by using fake job offers as lures to deploy malware and steal sensitive information. This emerging threat leverages the high demand for employment, especially in uncertain economic times, to ...
2 months ago Cybersecuritynews.com
Cyber Employment 2024: Sky-High Expectations Fail Businesses & Job Seekers - Well-publicized estimates of a massive shortfall in cybersecurity workers have resulted in high expectations among job seekers in the field, but the reality often falls flat, because of a mismatch between companies' requirements and job seekers' ...
1 year ago Darkreading.com Equation
CVE-2025-37763 - In the Linux kernel, the following vulnerability has been resolved: ...
7 months ago
Threat Actors Attacking Job Seekers With Three New Unique Adversaries - Their analysis revealed that operators typically employ multiple personas throughout the scam lifecycle – one to make initial contact and another to execute the fraud – allowing them to efficiently manage high volumes of victims while ...
6 months ago Cybersecuritynews.com
Hackers Posing as Google Careers Recruiter to Target Job Seekers - Cybercriminals are impersonating Google Careers recruiters to deceive job seekers and steal sensitive information. This sophisticated phishing campaign targets individuals looking for employment opportunities at Google, exploiting their trust in the ...
2 months ago Cybersecuritynews.com
North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers - A sophisticated North Korean advanced persistent threat (APT) group known as “Contagious Interview” has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware. Their investigation ...
7 months ago Cybersecuritynews.com Lazarus Group
New North Korean IT Worker With Innocent Job Application? - A recent cybersecurity investigation has uncovered a suspicious case involving a North Korean IT worker who submitted an apparently innocent job application. This case highlights the ongoing tactics used by North Korean threat actors to infiltrate ...
2 months ago Cybersecuritynews.com North Korean cyber groups