Hackers spear-phishing business professionals on LinkedIn with fake job offers and infecting them with malware warns eSentire.
eSentire, a leading cybersecurity solutions provider, is warning enterprises and individuals to beware of a new spear-phishing attack with fake job offers to infect them with a sophisticated backdoor Trojan.
Backdoor trojans give threat actors remote control over the victim’s computer, allowing them to send, receive, launch and delete files.
eSentire’s research team, the Threat Response Unit (TRU), revealed that hackers are spearphishing victims with a malicious zip file using the job position listed on the target’s LinkedIn profile.
For example, if the LinkedIn member’s job is listed as Senior Account Executive, International Freight the malicious zip file would be titled Senior Account Executive—International Freight position (note the “position” added to the end).
Upon opening the fake job offer, the victim without knowing initiates the stealthy installation of the fileless backdoor, more_eggs. Once loaded, the sophisticated backdoor can download additional malicious plugins and provide hands-on access to the victim’s computer.
The threat group behind more_eggs, Golden Chickens, sell the backdoor under a malware-as-a-service(MaaS) arrangement to other cybercriminals.
Once more_eggs is on the victim’s computer system, the Golden Eggs seedy customers can go in and infect the system with any type of malware: ransomware, credential stealers, banking malware, or simply use the backdoor as a foothold into the victim’s network to exfiltrate data.
“Three elements which make it a formidable threat to businesses and business professionals,” said Rob McLeod, Sr. Director of the Threat Response Unit (TRU) for eSentire. They are:
As yet, the TRU team has not discovered forensics indicating the identity of the hacking group which is trying to spearphish the LinkedIn members. Still, this malware-as a service has been used by three notable threat groups: FIN6, Cobalt Group, and Evilnum.
You can follow us on Linkedin, Twitter, Facebook for daily Cyber security and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…