A Job Applicant? Nope, Its A Malware Attack

  /     /     /  
Publicated : 22/11/2024   Category : security


A Job Applicant? Nope, Its A Malware Attack


Cybercriminals burying malicious code in responses to job postings, IC3 says



Cybercriminals engaging in ACH/wire transfer fraud are targeting businesses by responding via email to employment opportunities posted online, according to federal authorities.
A
warning from the Internet Crime Complaint Center
yesterday stated that more than $150,000 was stolen from a U.S. business via unauthorized wire transfer as a result of an email the business received that contained malware.
According to FBI researchers, the malware was embedded in an email response to a job posting the business placed on an employment website and allowed the attacker to obtain the online banking credentials of the person who was authorized to conduct financial transactions within the company.
The malicious actor changed the account settings to allow the sending of wire transfers -- one to the Ukraine and two to domestic accounts. The malware was identified as a Bredolab variant, svrwsc.exe. This malware was connected to the Zeus/Zbot Trojan, which is commonly used by cybercriminals to defraud businesses.
The FBI recommends that potential employers remain vigilant in opening the emails of prospective employees. The agency advises running a virus scan prior to opening any email attachments, and says businesses should use separate computer systems to conduct financial transactions.
Have a comment on this story? Please click Discuss below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
A Job Applicant? Nope, Its A Malware Attack