Proofpoint has warned recruiters of a skilled threat actor targeting them with emails designed to deploy malware.
TA4557 is a financially motivated threat actor known to distribute the More Eggs backdoor, which is designed to establish persistence, profile the targeted machine and drop additional payloads.
Throughout 2022 and most of 2023 the actor has been replying to open job listings on third-party job boards and, more recently, targeting recruiters direct.
If they follow these instructions and visit the sender's website, they will be presented with a CAPTCHA page, which, if completed, will begin a download of a zip file containing a shortcut file.
Proofpoint urged recruiters to update their user awareness training to mitigate the threat posed by TA4557, which is also linked to FIN6.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Tue, 12 Dec 2023 10:40:12 +0000