Hiring Trap: Threat Actors Exploit Job Portals to Breach Corporate Systems

Amber | Attack Report
Download PDF

Venom Spider is launching a phishing campaign targeting HR departments. The attackers disguise emails as job applications, delivering an updated version of their More_eggs backdoor malware. The attack tricks HR professionals into downloading a ZIP file containing a malicious shortcut, which uses “living-off-the-land” techniques to execute a hidden JavaScript payload. This malware creates multiple files, evades detection, and opens a backdoor for long-term system access. The attack is difficult to trace due to the use of anonymous cloud services and multi-layered URLs.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox