Google Warns of Cybercriminals Using Fake Job Postings to Spread Malware and Steal Credentials
## Cybersecurity: Threat Intelligence Update
Cybersecurity: Threat Intelligence Update
Google's Threat Intelligence Group (GTIG) has identified a sophisticated social engineering campaign orchestrated by financially motivated threat actors, UNC6229, based in Vietnam. The campaign targets corporate advertising accounts to steal credentials for resale or direct monetization.
The campaign specifically focuses on remote workers in digital advertising roles, targeting individuals with contract or part-time positions actively seeking employment. By compromising these workers' devices or stealing their credentials, UNC6229 gains unauthorized access to high-value corporate advertising and social media accounts. The group exploits job seekers' trust by posting fake career opportunities on legitimate employment platforms to deliver malware and phishing kits targeting the digital advertising and marketing sectors.
Once breached, threat actors monetize these accounts by either selling advertisements through them or transferring ownership to other malicious actors. Google has shared its findings with the security community and has added identified malicious infrastructure to its Safe Browsing blocklist to protect users across major browsers.
This campaign exploits the trust inherent in legitimate job applications. UNC6229 creates convincing fake company profiles on popular employment platforms, masquerading as digital media agencies and recruiters. When job seekers apply for these fabricated positions, they unwittingly provide personal information, contact details, and resumes. This victim-initiated action establishes a foundation of trust that the threat actors leverage in subsequent interactions.
The attackers retain victims' personal information for future targeting or sell curated lists of active job seekers to other threat actors. By using legitimate job platforms alongside custom-built fake job websites, UNC6229 significantly increases its campaign's reach and credibility.
The campaign targets corporate advertising accounts to steal credentials for resale or direct monetization.
Upon a victim's application, UNC6229 initiates personalized contact through email or direct messaging platforms. The initial outreach references the specific job application and addresses victims by name to build rapport without raising suspicion. GTIG discovered that threat actors abuse legitimate business tools, including CRM platforms like Salesforce, Google Groups, and Google AppSheet, to send bulk emails and manage campaigns.
After establishing rapport, the threat actors proceed to payload delivery. In some campaigns, victims receive password-protected ZIP files disguised as skills assessments, application forms, or preliminary hiring tasks. These archives contain remote access trojans (RATs) that grant attackers full control over victims' devices, enabling account takeover and credential theft.
In other variants, victims receive obfuscated links directing them to phishing pages designed to harvest corporate credentials. Analysis of phishing kits associated with UNC6229 reveals sophisticated credential-stealing infrastructure specifically configured to target corporate email accounts and multi-factor authentication schemes.
The "fake career" lure exploits fundamental human behaviors and professional necessity. Unlike traditional phishing campaigns, victims believe they are initiating legitimate business contact with potential employers, making them more susceptible to manipulation. The combination of patience, personalization, and abuse of legitimate commercial platforms demonstrates the threat cluster's operational maturity and resource availability.
GTIG assesses with high confidence that UNC6229 operates as a collaborative cluster of financially motivated individuals sharing tools, techniques, and infrastructure. The group's success with digital advertising workers suggests expansion to other industries where employees access valuable corporate assets.
Organizations must enhance employee awareness training and implement robust account security measures to defend against these evolving threats.
Based on reporting by GBHackers.
