PULSE NAME
Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials
WHITE UNC6229 AlienVault 2025-10-23 Modified: 2025-10-24
10
IOCs
LOW VOLUME
A group of financially motivated threat actors from Vietnam, tracked as UNC6229, is targeting individuals in the digital advertising and marketing sectors through fake job postings. They use social engineering tactics to deliver malware and phishing kits, aiming to compromise high-value corporate accounts and hijack digital advertising accounts. The attackers create fake company profiles on legitimate job platforms, luring applicants with attractive remote job openings. Once contact is established, they send malware attachments or phishing links, often abusing legitimate business and CRM platforms to appear credible. The campaign's success relies on victim-initiated contact and targets remote digital advertising workers with access to company ad accounts.
Indicators of Compromise (10)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2306c3bc37df52bf26b722f6d5015bb2 2025-10-23
FileHash-MD5 6da534ee1f9346c4c313d7ea582d1bec 2025-10-23
FileHash-SHA1 5c37901388830b910d3b5fdfe32ce0d0784e0628 2025-10-23
FileHash-SHA1 81a59d6e92f35bb09bbe5c3f804d2ec3f9e50dbd 2025-10-23
FileHash-SHA256 137a6e6f09cb38905ff5c4ffe4b8967a45313d93bf19e03f8abe8238d589fb42 2025-10-23
FileHash-SHA256 33fc67b0daaffd81493818df4d58112def65138143cec9bd385ef164bb4ac8ab 2025-10-23
FileHash-SHA256 35721350cf3810dd25e12b7ae2be3b11a4e079380bbbb8ca24689fb609929255 2025-10-23
FileHash-SHA256 bc114aeaaa069e584da0a2b50c5ed6c36232a0058c9a4c2d7660e3c028359d81 2025-10-23
FileHash-SHA256 e1ea0b557c3bda5c1332009628f37299766ac5886dda9aaf6bc902145c41fd10 2025-10-23
domain staffvirtual.website 2025-10-23