Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Google Warns of Cybercriminals Using Fake Job Postings to Spread Malware and Steal Credentials

## Cybersecurity: Threat Intelligence Update

Cybersecurity: Threat Intelligence Update

Google's Threat Intelligence Group (GTIG) has identified a sophisticated social engineering campaign orchestrated by financially motivated threat actors, UNC6229, based in Vietnam. The campaign targets corporate advertising accounts to steal credentials for resale or direct monetization.

The campaign specifically focuses on remote workers in digital advertising roles, targeting individuals with contract or part-time positions actively seeking employment. By compromising these workers' devices or stealing their credentials, UNC6229 gains unauthorized access to high-value corporate advertising and social media accounts. The group exploits job seekers' trust by posting fake career opportunities on legitimate employment platforms to deliver malware and phishing kits targeting the digital advertising and marketing sectors.

Once breached, threat actors monetize these accounts by either selling advertisements through them or transferring ownership to other malicious actors. Google has shared its findings with the security community and has added identified malicious infrastructure to its Safe Browsing blocklist to protect users across major browsers.

This campaign exploits the trust inherent in legitimate job applications. UNC6229 creates convincing fake company profiles on popular employment platforms, masquerading as digital media agencies and recruiters. When job seekers apply for these fabricated positions, they unwittingly provide personal information, contact details, and resumes. This victim-initiated action establishes a foundation of trust that the threat actors leverage in subsequent interactions.

The attackers retain victims' personal information for future targeting or sell curated lists of active job seekers to other threat actors. By using legitimate job platforms alongside custom-built fake job websites, UNC6229 significantly increases its campaign's reach and credibility.

The campaign targets corporate advertising accounts to steal credentials for resale or direct monetization.
William Hayes · Thehackingpost

Upon a victim's application, UNC6229 initiates personalized contact through email or direct messaging platforms. The initial outreach references the specific job application and addresses victims by name to build rapport without raising suspicion. GTIG discovered that threat actors abuse legitimate business tools, including CRM platforms like Salesforce, Google Groups, and Google AppSheet, to send bulk emails and manage campaigns.

After establishing rapport, the threat actors proceed to payload delivery. In some campaigns, victims receive password-protected ZIP files disguised as skills assessments, application forms, or preliminary hiring tasks. These archives contain remote access trojans (RATs) that grant attackers full control over victims' devices, enabling account takeover and credential theft.

In other variants, victims receive obfuscated links directing them to phishing pages designed to harvest corporate credentials. Analysis of phishing kits associated with UNC6229 reveals sophisticated credential-stealing infrastructure specifically configured to target corporate email accounts and multi-factor authentication schemes.

The "fake career" lure exploits fundamental human behaviors and professional necessity. Unlike traditional phishing campaigns, victims believe they are initiating legitimate business contact with potential employers, making them more susceptible to manipulation. The combination of patience, personalization, and abuse of legitimate commercial platforms demonstrates the threat cluster's operational maturity and resource availability.

Advertisement

GTIG assesses with high confidence that UNC6229 operates as a collaborative cluster of financially motivated individuals sharing tools, techniques, and infrastructure. The group's success with digital advertising workers suggests expansion to other industries where employees access valuable corporate assets.

Organizations must enhance employee awareness training and implement robust account security measures to defend against these evolving threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories