Cybercriminals use malware-laced CVs to steal banking credentials

Banking
(Image credit: Shutterstock)

Security researchers have discovered malicious files masquerading as CVs online that lure victims into giving up their banking passwords and other financial information.

According to Check Point, the malicious Microsoft Excel files were sent via email with subject lines such as “applying for a job” or “regarding job”. When victims open the attached files, they are asked to “enable content” and this allows for the ZLoader malware to be installed on their computers. This banking malware is designed to steal credentials and other private information from users of targeted financial institutions.

The malware also has the ability to steal any passwords and cookies stored in victim's web browsers. Using this stolen information, cybercriminals can then connect to the victim's system and make illicit financial transactions from the banking user's legitimate device.

Check Point researchers have recently seen an increase in CV-themed scams in the US. During the past two months, the number of malicious files in CVs doubled with 1 out of 450 malicious files identified related to a CV file as cybercriminals try to exploit layoffs and remuneration schemes during the pandemic.

Malicious medical leave forms

In addition to CVs containing malicious files, Check Point researchers also found an increase in malicious medical leave forms circulating online.

The documents, which use names such as “COVID -19 FLMA Center.doc”, infect victims with the IcedID banking malware that targets banks, payment card providers, mobile service providers and e-commerce sites.

The aim of this malware is to try and trick users into submitting their credentials on a fake page as well as their authorization details that can be used to compromise user accounts. These malicious files were sent via email with the subject line “The following is a new Employee Request Form for leave within the Family and Medical Leave Act (FMLA)”. To lure victims into opening these forms, cybercriminals sent them from different sender domains like “medical-center.space”.

Manager of data intelligence at Check Point, Omer Dembinsky provided further insight on the findings of the company's researchers, saying:

“As unemployment rises, cyber criminals are hard at work. They are using CVs to gain precious information, especially as it relates to money and banking. I strongly urge anyone opening an email with a CV attached to think twice. It very well could be something you regret.”

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Latest in News
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
DJI Mavic 3 Pro
More DJI Mavic 4 Pro leaks seemingly reveal launch date, price and key features of the triple camera drone – here's what to expect
Android 16 logo on a phone
Here's how Android 16 will upgrade the screen unlocking process on your Pixel
Man sitting on sofa, drinking coffee, looking at phone in surprise
Thousands of coffee lovers warned to stop using their espresso machines immediately after reports of burns and lacerations