近日,安全公司WithSecure发布新闻稿称,他们发现了一起越南黑客在领英冒充美商海盗船HR向求职者发送包含恶意木马DarkGate、RedLine Stealer的邮件的事件。
According to WithSecure, in a recent attack case that occurred in August, hackers sent job seekers emails pretending to be from HR at the company and asked them to download employment-related documents by clicking on a specific link. Once these documents were downloaded and opened, malicious VBS code was executed automatically, infecting the computer with DarkGate malware.
Furthermore, after installation of the malware within thirty seconds, it attempted to uninstall WithSecure software but without success. It is important to note that this particular malware was found alongside other variants such as Ducktail, DarkGate variant 1299539478, RedLine Stealer, and Lobshot.
WithSecurity believes this may be the same group behind the previous distribution of Ducktail malware; thus they advise job seekers to exercise caution while downloading employment-related files sent by HR personnel within LinkedIn or other platforms.