PULSE NAME
Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials
WHITE UNC6229 AlienVault 2025-10-23 Modified: 2025-10-24
10
IOCs
LOW VOLUME
A group of financially motivated threat actors from Vietnam, tracked as UNC6229, is targeting individuals in the digital advertising and marketing sectors through fake job postings. They use social engineering tactics to deliver malware and phishing kits, aiming to compromise high-value corporate accounts and hijack digital advertising accounts. The attackers create fake company profiles on legitimate job platforms, luring applicants with attractive remote job openings. Once contact is established, they send malware attachments or phishing links, often abusing legitimate business and CRM platforms to appear credible. The campaign's success relies on victim-initiated contact and targets remote digital advertising workers with access to company ad accounts.
Indicators of Compromise (2 / 10 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 5c37901388830b910d3b5fdfe32ce0d0784e0628 2025-10-23
FileHash-SHA1 81a59d6e92f35bb09bbe5c3f804d2ec3f9e50dbd 2025-10-23