PULSE NAME
Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials
WHITE UNC6229 AlienVault 2025-10-23 Modified: 2025-10-24
10
IOCs
LOW VOLUME
A group of financially motivated threat actors from Vietnam, tracked as UNC6229, is targeting individuals in the digital advertising and marketing sectors through fake job postings. They use social engineering tactics to deliver malware and phishing kits, aiming to compromise high-value corporate accounts and hijack digital advertising accounts. The attackers create fake company profiles on legitimate job platforms, luring applicants with attractive remote job openings. Once contact is established, they send malware attachments or phishing links, often abusing legitimate business and CRM platforms to appear credible. The campaign's success relies on victim-initiated contact and targets remote digital advertising workers with access to company ad accounts.
Indicators of Compromise (5 / 10 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 137a6e6f09cb38905ff5c4ffe4b8967a45313d93bf19e03f8abe8238d589fb42 2025-10-23
FileHash-SHA256 33fc67b0daaffd81493818df4d58112def65138143cec9bd385ef164bb4ac8ab 2025-10-23
FileHash-SHA256 35721350cf3810dd25e12b7ae2be3b11a4e079380bbbb8ca24689fb609929255 2025-10-23
FileHash-SHA256 bc114aeaaa069e584da0a2b50c5ed6c36232a0058c9a4c2d7660e3c028359d81 2025-10-23
FileHash-SHA256 e1ea0b557c3bda5c1332009628f37299766ac5886dda9aaf6bc902145c41fd10 2025-10-23