HomeSecurityAryaka: Resumes with malicious ISO attachments are circulating

Aryaka: Resumes with malicious ISO attachments are circulating

Malicious actors continue to be successful in tricking HR staff into opening phishing emails infected with malicious ISO files. The latest example is described by researchers at Aryaka, who this week described a campaign by an unknown malicious actor distributing resumes containing a malicious ISO file to HR departments.

See also: Phantom Stealer: Phishing attack with ISO images targets Russia

ISO

This is delivered via recruitment channels and hosted on cloud infrastructure that an employee or the filters of an email gateway would see as trusted. When the victim mounts the ISO, which is a file of an optical disc like a DVD and opens its contents, a malicious shortcut (.lnk) is executed, launching concealed PowerShell commands that extract hidden payloads embedded in a steganographic image.

A malicious DLL is then loaded using a legitimate, signed application, allowing the attacker's code to run under the guise of trusted software. The goal is to collect data from the infected computer. The most worrying feature of the malware, Aryaka says, is an internal module called BlackSanta, which disables endpoint detection and response (EDR) agents that would detect this attack.

It uses a Bring-Your-Own Vulnerable Driver (BYOVD) technique that loads legitimate but exploitable kernel drivers, gaining low-level system access, and then systematically disables security tools. While this is a sophisticated attack, what CSOs may find more important is preventing the attack in the first place by providing security awareness training to HR employees to help them spot phishing baits.

See also: Traditional security frameworks leave organizations exposed to AI attacks

Aryaka: Resumes with malicious ISO attachments are circulating
Aryaka: Resumes with malicious ISO attachments are circulating

Among the priorities for this training: Emphasis on the fact that files ending in .iso can execute malicious software. A résumé or job application file should end in .docx, .pdf or .txt.

“Your HR team should be among your most trained and protected employees,” says Roger Grimes, CISO at awareness training provider KnowBe4.

The HR staff should be trained to accept only standard resume submission document types, such as .pdf or .docx, Grimes said, and not click on URLs within them unless necessary. Some organizations reduce the risk of sending malicious software via fake resumes by requiring all submissions to go to the HR recruitment portal, which accepts only text inputs in provided web forms, he added.

At a minimum, all HR staff members must understand that they are at high risk of falling for scams, he said. They need to be trained on the common scams targeting HR departments, be guided when performing high‑risk actions, and undergo phishing tests that mimic the phishing that typically targets HR employees.

See also: New ForumTroll Phishing Attacks Target Russian Academics

Aryaka: Resumes with malicious ISO attachments are circulating
Aryaka: Resumes with malicious ISO attachments are circulating

The fake job applications are not only accompanied by malicious software. In an era where many job positions are filled using online interviews, they serve as a way for states to infiltrate sensitive organizations such as defense or government contractors. Last month, a Ukrainian was sentenced by a US judge to 60 months in prison for stealing American identities, which were then used by North Koreans to obtain malicious employment in American companies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS