Beware — that dream job offer could be malware sent by Iranian hackers
- Iranian state-sponsored actors are targeting aerospace pros with fake jobs
- The goal is to install backdoors and exfiltrate important data
- The style mimics that of Lazarus, a known North Korean actor
Iranian state-sponsored hackers have been observed targeting victims in the aerospace industry with fake job offers, which resulted in the deployment of the SnailResin malware, as part of their cyber-espionage campaign.
Cybersecurity researchers at ClearSky revealed how the threat actor, known as TA455, created fake recruitment sites, and fake profiles on social media sites such as LinkedIn. After that, they would approach their targets, and get them to download files as part of the onboarding process.
Among the files was SnailResin, a piece of malware that acts as a loader for the SlugResin backdoor, capable of data exfiltration, command-and-control (C2) communication, and persistence on victim systems.
Iranians? Or North Koreans? Or both?
The campaign, dubbed “Dream Job” started in September 2023, if not earlier, ClearSky noted.
TA455 is a well-known cyberespionage group, linked with Iran’s Islamic Revolutionary Guard Corps (IRGC), and shares similarities with other groups like APT35 and TA453. Besides the aerospace industry, TA455 was seen targeting defense, and government entities, in the Middle East, Europe, and the US. Its goal, for the most part, is cyber-espionage, gathering sensitive information for geopolitical intelligence purposes.
What makes this campaign particularly interesting is the fact that it mimics the style of Lazarus, a North Korean state-sponsored group. Fake job attacks are basically synonymous with Lazarus at this point, as they were used in some of the most destructive campaigns against firms in the crypto industry. At this point, ClearSky doesn’t know if TA455 is mimicking Lazarus, tries to hide behind the group, or is in cooperation with them.
“The similar “Dream Job” lure, attack techniques, and malware files suggest that either Charming Kitten was impersonating Lazarus to hide its activities, or that North Korea shared attack methods and tools with Iran,” they said.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In any case, be careful when getting new job offers, especially if they sound too good to be true.
You might also like
Iranian state-sponsored actors are targeting aerospace pros with fake jobs The goal is to install backdoors and exfiltrate important data The style mimics that of Lazarus, a known North Korean actor Iranian state-sponsored hackers have been observed targeting victims in the aerospace industry with fake job offers, which resulted in…
Recent Posts
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Cash App made a magic wand for contactless payments
- Wave Cash App’s Magic Wand to Pay for Stuff
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023