A new group of hackers, dubbed “ResumeLooters,” seekers jobafter breaching 65 legitimate job listing and retail sites. The breaches were carried out through SQL injection and cross-site scripting (XSS) attacks.

The hackers mainly targeted sites in Australia, Taiwan, China, Thailand, India and Vietnam and stole various data, such as names, email addresses, phone numbers, employment history, education and other relevant information that a person provides when looking for a job.
These attacks were detected by Group-IB, which has been tracking the hacking group since at least November 2023. According to the researchers, ResumeLooters attempted to sell the stolen data via Telegram.
See also: Deepfake scam: How a fake conference call led to the theft of $25 million
As we mentioned earlier, the hackers used SQL injection and XSS (common tactics for them) to compromise targeted websites, mainly job boards and retail stores.
The pen-testing phase included the use of open source tools such as:
- SQLmap: Automates the detection and exploitation of SQL injection errors by taking control of database servers.
- Beef Framework: Exploits browser vulnerabilities.
- Acunetix: An online vulnerability scanner that detects common security, such as XSS and SQL injection, and provides remediation reports.
- ARL (Asset Reconnaissance Lighthouse): Scans and maps online assets, identifying potential vulnerabilities in the network infrastructure.
- X-Ray: Detects web application vulnerabilities.
- Metasploit: Develops and executes exploit code against targets.
- Dirsearch: Command-line tool for brute-forcing directories and files in web applications, revealing hidden resources.
See also: Have I Been Pwned: Adds 71 million emails from Naz.API account theft list
After identifying and exploiting security vulnerabilities in target websites, ResumeLooters hackers insert malicious scripts into multiple locations in a website's HTML.
With a successful SQL injection, a malicious remote script will be executed that displays phishing forms to steal visitors' information.
According to Group-IB researchers, in some cases, hackers used customized attack techniques. For example, they created fake employer profiles and shared fake resumes that contained XSS scripts.

However, thanks to an opsec error by the attackers, Group-IB managed to penetrate the database hosting the stolen data, and realized that the attackers had administrator access to some of the compromised websites.
The ResumeLooters hackers are stealing the data for financial gain, after attempting to sell it to other cybercriminals through at least two Telegram accounts that use Chinese names, namely “注意思中心” (Penetration Data Center) and “万国意思阿or力” (World Data Ali).
See also: Fake 401K year-end statements used to steal corporate credentials
Group-IB has not disclosed the origin of the ResumeLooters hackers. However, evidence suggests that they are selling the data to Chinese-speaking groups using Chinese versions of toolssuch as X-Ray.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The consequences for people who fall victim to data theft are many and serious. First, identity can be used for illegal activities, such as credit card fraud or identity theft.
Secondly, their financial situation can be negatively affected, as hackers may try to gain access to bank accounts. This can lead to debt or even financial ruin.
Third, the leaked information may include sensitive data, such as medical information or information about family and personal life. This can lead to breaches of privacy and trust.
Finally, the psychological impact can be enormous. People who fall victim to such attacks can feel helpless, betrayed, and insecure. This can lead to stress, anxiety, and other psychological problems.
Source: www.bleepingcomputer.com
