Description
The FIN6 threat group, also known as “Skeleton Spider,” has launched a sophisticated social engineering campaign targeting human resource (HR) professionals and recruiters. Unlike typical employment scams, this operation flips the script: instead of luring job seekers, FIN6 impersonates job applicants to deceive recruiters into visiting phishing websites and downloading malware. This latest operation leverages the More_eggs malware-as-a-service backdoor to gain unauthorized access to systems, steal credentials, and deploy additional payloads, including ransomware.
Attack Details
In the newly identified campaign, FIN6 actors use fake job seeker personas to approach recruiters on professional platforms such as LinkedIn and Indeed. Once contact is established, the threat actors follow up via email, sharing a non-clickable URL to a supposed resume or portfolio site. These links are intentionally not hyperlinked, forcing targets to manually enter them into their browsers, an evasion tactic that helps avoid automated security filters.
The phishing domains, registered anonymously through GoDaddy and hosted on Amazon Web Services (AWS), mimic professional portfolio sites. These domains include advanced evasion techniques:
Once victims pass the CAPTCHA, they are prompted to download a ZIP archive allegedly containing a resume. In reality, it hides a malicious Windows shortcut (LNK) file that triggers a script to download and install More_eggs, a versatile JavaScript backdoor developed by another actor, “Venom Spider.”
More_eggs capabilities include:
Indicators of Compromise (IOCs)
Domains associated with this campaign:
Malware:
File type used in phishing package:
Hosting infrastructure:
Tactics:
Remediation
Organizations, especially HR departments and recruiters, should implement the following security measures:
The Guyana National CIRT recommends that users and administrators review this alert and apply it where necessary.
PDF Download: FIN6 Hackers Pose as Job Seekers to Backdoor Recruiters Devices
References