Cyber Security News

Hackers Use Fake Student Resume to Secretly Install Malware on Researchers’ Computers

A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background.

The lure claims to come from a recent Beijing Institute of Technology graduate seeking research work in electrical engineering, energy systems and applied AI.

That focus points to professors and laboratory staff as likely targets, rather than ordinary corporate recruiters, and turns academic correspondence into a route for intrusion.

Himanshu Anand said in a report shared with Cyber Security News (CSN) that the attack delivers SNOWLIGHT and the VShell remote-access trojan through a multi-stage, memory-based chain.

The evidence supports targeted access to a research workstation, but does not establish the operator’s identity, nationality or final objective.

The resume-to-RAT chain (HimanshuAnand)

The incident shows why academic staff need the same caution applied to hiring teams. A believable application exploits the expectation that researchers will review unfamiliar files, while the decoy document gives victims little reason to suspect trouble.

Fake Resume Targets Researchers

The malicious ZIP archive uses a Chinese-language name that presents its supposed author as Zhang Yuguang, a network-engineering graduate. Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.

Once opened, the loader retrieves and launches a real DOCX resume, allowing the recipient to read the expected application.

At the same time, it checks for an analysis environment, refuses systems with fewer than four CPU cores, and uses an unusual timing test before continuing.

The decoy makes claims about AI-based power-grid fault diagnosis, renewable-energy control and joining a supervisor’s research group, suggesting that the attacker tailored it for technical academics.

VShell Flow (HimanshuAnand)

Similar lures appear in this report on academic event material attacks, where trusted research context also served as cover. The university name gives the application credibility, but it is not evidence that the institution created, knew about or received the malware.

Anand assessed a mainland Chinese academic recipient as the most likely target context, while keeping attribution to the operator unresolved.

The initial program downloads encrypted shellcode and runs it in memory instead of saving a conventional payload to disk. This fileless approach can make routine disk-based checks less useful, as explained in coverage of how fileless malware works, while allowing the decoy to stay open.

SNOWLIGHT Opens Remote Access

The Windows SNOWLIGHT shellcode contacts the command server, sends a short system check-in and receives a 4.65 MB payload. It decodes that payload and transfers execution to VShell, which registers with the same server over encrypted traffic.

That sequence gave the attackers a remote-access foothold. The sample completed VShell registration and health checks, although the analysis did not capture an operator typing commands, transferring files or moving to another system.

Confirmed behavior must remain separate from capabilities that could be used later. VShell can provide an interactive command shell, file transfer, screen capture, network discovery and tunneling.

Its wider campaign use is examined in VShell threat actor adoption, but the framework alone does not identify a particular threat group.

That distinction matters here. SNOWLIGHT and VShell have appeared in activity associated with several clusters, yet are now available more widely.

The report therefore describes an unattributed actor using a mainland-China-oriented academic lure, not a confirmed state-linked operation.

Researchers, departments and IT teams should verify unsolicited applications through a separate contact channel before opening files.

They should enable visible extensions, block executable content in unexpected archives, and investigate resume-themed programs that start command shells, Word or unusual outbound connections.

Similar recruitment scams have targeted business teams through fake resume malware campaigns, showing that the social-engineering pattern extends beyond academia.

Security teams should hunt for the listed network destinations, resume-themed executables and the temporary marker associated with this chain, reviewing related process and network telemetry.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Archive filenameBeijing Institute of Technology_network engineering major_fresh graduate_Zhang Yuguang_personal resume (2)(1).zipMalicious archive used as the initial delivery container
SHA-256c25d4412f7f93e7de5b2aaf41747175d94cffd983ca20efbd0efcdd718b58c4dOriginal malicious archive
SHA-25681c51138d5527ca7dcc258171eb36659c479f66c86a8947b6340d040b3860a30Go loader
MD5a7cc7e3cdd2f0f9210044911a483fa5dGo loader
SHA-256f6d4da5afc89bf9e536a9002c4d256c696df2389d77279f4c5daf6979557e74eEncrypted HTTP response
SHA-2560524619d2471d77aba4b7993f5ffbaa4b8be6d2c0d91e63a02943851dc4b6404SNOWLIGHT shellcode
SHA-256ed2eaa6ef3eda95383b6efc35b88acbca742ad7bd118931f74727a3139ff7e97XOR-encoded VShell payload stream
SHA-256c666ac4f1a1b8df7ccfe8b19705279acd8b7eb7a4d0b3802bb3465064883ab25Decoded VShell payload
SHA-256de3f56d0d5b71f2a1a1905f0b01b84fbab237e9d4c5179a05b127d806823f83cDOCX resume decoy
IP address38.207.178.192Campaign command-and-control and staging server
URLhttp://38.207.178.192:50813/EasyConnectUpdata_Log.txtEncrypted shellcode staging location
URLhttp://38.207.178.192:50813/MySQL_LOG.txtWord document decoy staging location
Network service38.207.178.192:50813HTTP staging service
Network service38.207.178.192:50812SNOWLIGHT check-in and VShell transfer service
AES keyYtWzxwZimsZoeMenEmbedded loader configuration decryption key
XOR key0x99Key used to decode the received VShell payload
FilenameTEMPde.logSNOWLIGHT kill-switch or operator exclusion marker

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm

Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…

1 hour ago

Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption

Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…

4 hours ago

Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code

Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…

5 hours ago

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…

5 hours ago

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…

7 hours ago

100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks

More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…

8 hours ago