Tech »  Topic »  Fake Job Offers Used to Deliver Advanced Malware Targeting Job Seekers

Fake Job Offers Used to Deliver Advanced Malware Targeting Job Seekers


By Mayura Kathir

Iranian threat actors are exploiting job seekers’ aspirations through sophisticated fake recruitment campaigns designed to deploy advanced malware across Europe’s critical infrastructure sectors.

The attack methodology demonstrates remarkable operational security and state-sponsored tradecraft characteristics.

Nimbus Manticore, also known as UNC1549 or Smoke Sandstorm, constructs elaborate fake recruitment websites that impersonate major aerospace companies including Boeing, Airbus, Rheinmetall, and flydubai.

Check Point Research has identified an alarming expansion of operations by Nimbus Manticore, a mature Iran-nexus advanced persistent threat (APT) group, targeting defense, telecommunications, and aerospace organizations with unprecedented sophistication.

These deceptive portals utilize React templates that dynamically adapt to match the branding of targeted organizations, creating convincing replicas of legitimate career pages.

Diagram of the Advanced Persistent Threat (APT) lifecycle highlighting key stages from preparation to cleanup of cyberattack operations

What sets these campaigns apart is their controlled access mechanism. Each potential victim receives unique login ...


Copyright of this story solely belongs to gbhackers . To see the full text click HERE