Watch out - that dream job applicant could actually just be damaging malware

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Cybersecurity company Proofpoint has warned of an attacker employing a variety of methods to spread malware within organizations, and the latest technique is just as easy to fall for as it is to spot.

The attack, attributed to a financially motivated threat actor known as TA4557, impersonates a job applicant and uses attachments like PDFs and Word documents or malicious websites to spread malware.

According to Proofpoint, TA4557 has been using advanced social engineering tactics since 2018, including similar job applicant-type attacks for the last two years.

Recruiters beware

The latest method, which has been used since at least October 2023, begins with a benign email expressing interest in an open role.

From there, the chain between the recruiter and the malicious applicant continues, whereby the applicant finally engages in the attack. A resume, supposedly hosted on the applicant’s personal website, is shared with the victim.

The legitimate-looking website hosts a downloadable .zip file which includes a shortcut file (LNK). Ultimately, the malware exists to gain unauthorized access to a victim’s machine and then to drop additional payloads.

In some cases, the threat actor shared details of the malicious website via email attachments, including PDF and Word documents.

Of the two screenshots shared on Proofpoint’s blog, both use custom email domains and direct the recruiter to a website using that same domain.

According to Proofpoint, there’s been a recent uptick in the number of social engineering scams using benign emails. The cybersecurity firm added:

“Organizations that use third-party job posting websites should be aware of this actor’s tactics, techniques, and procedures (TTPs) and educate employees, especially those in recruiting and hiring functions, about this threat.”

More from TechRadar Pro

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
A digital representation of a lock
Looking for a new job? Watch out you don't fall for this new malware scam
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)