A new social engineering is being adopted by the notorious hacking group FIN6, which is targeting recruiters. Instead of pretending to be recruiters to lure unsuspecting candidates – as is common in job scams – FIN6 members are posing as job candidates, presenting seemingly authentic resumes and phishing websites to distribute malware.

The group, also known as Skeleton Spider, has a history of financial fraud, with a particular focus on hacking point-of-sale (PoS) terminals to steal credit card data. However, since 2019, its activity has shifted to more aggressive forms of attack, such as spreading ransomware (collaborating with notorious operations such as Ryuk and LockerGoga).
See also: Marks & Spencer: Hackers sent threatening email to CEO
FIN6: New attacks target recruiters
According to a new report from DomainTools, the attacks are starting via popular professional networking platforms like LinkedIn and Indeed, where cybercriminals create fake profiles candidates of job recruiters, cultivating a climate of trust before sending phishing emails.
The phishing messages are well-written and professional, containing links to supposedly websites hosting resumes. However, the links are presented as non-clickable — a tactic designed to bypass security filtersby forcing recipients to manually type the address into their browser.
The FIN6 leverages fake websites hosted on AWS, registered anonymously through GoDaddy, to bypass traditional security filters and trap recruiters.
The domains, which are based on the fake personas used in the attacks, remain indistinguishable to threat detection, thanks to their hosting in trusted cloud environments.
Examples of phishing domains
Some of the domains that have been recorded in the campaign include:
bobbyweisman[.]comemersonkelly[.]comdavidlesnick[.]comkimberlykamara[.]comannalanyi[.]combobbybradley[.]netmalenebutler[.]comlorinash[.]comalanpower[.]netedwarddhall[.]com
All of these websites are presented as professional portfolios, however, they are carefully designed to be activated only in specific contexts, by the selected targets.
See also: Hackers exploit old AT&T data breach
FIN6 has built-in intelligent environmental fingerprinting , blocking access from Linux/macOS and visits via VPN and cloud services. In these cases, neutral content, hiding the activity from security researchers.
When a target meets the desired criteria, they are taken to a fake CAPTCHA, which is the final stage before being asked to download a seemingly innocent ZIP file. Instead of a resume, the file contains a malicious LNK (Windows shortcut), designed to execute a script that installs the “More Eggs” backdoor on the victim’s system.
More_eggs malware
More_eggs , an advanced backdoor attributed to a group known as Venom Spider , has resurfaced as a key tool in the hands of FIN6 . It is a modular backdoor , capable of executing commands, stealing credentials , deploying additional payloads, and leveraging PowerShell for further penetration.
The approach adopted by FIN6 is characterized by simplicity but high effectiveness, utilizing social engineering techniques and advanced methods of evading detection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Warning to HR and hiring managers
Human resources professionals are urged to exercise increased caution when requesting resume verification from external links, especially when files are required to be downloaded from unknown websites.
See also: ConnectWise: State hackers behind the cyberattack?
Companies and recruitment agencies should adopt additional verification steps, such as direct contact with individuals and contacting past employers mentioned by candidates in early interviews.
Amazon's response to the use of AWS in the campaign
Regarding the malicious use of the AWS to host FIN6 domains, an Amazon commented to BleepingComputer:
«AWS has strict terms that require customers to comply with applicable laws. When we receive reports of potential violations, we move quickly to investigate and disable any content that violates our rules. We value collaboration with the cybersecurity community and encourage researchers to report incidents to us through the formal AWS Trust & Safety process.».
Phishing protection
Given that infections occur via phishing emails, it is important to know how you can protect yourself from this threat:
Be wary of unexpected emails: If you receive an email from an unknown sender that asks for sensitive information or asks you to open or download a file, be cautious. Always verify the purported sender through a separate communication channel before responding.
Check URLs: Hover over any links in the email and check if they match the URL shown in the email body. If they don't match, it could be a sign of fraud.
Don't open attachments from unknown sources: Opening attachments from unknown senders can potentially infect computer with malware or ransomware. If you're unsure about an attachment, don't risk it.
Use multi-factor authentication: This adds an extra layer of security by requiring more than one password to access accounts and systems. It can prevent hackers from gaining access even if they have obtained login credentials through a spear-phishing attack.
Stay up to date on new threats: Stay up to date on the latest methods used in spear-phishing attacks and learn how to recognize them.
Use anti-phishing software: There are several anti-phishing tools available that can help detect and prevent these attacks. Consider using one for added protection.
Source: www.bleepingcomputer.com
