Fake Jobs, Real Malware. Uncovering How Cybercriminals are Exploiting the Employment Market

2025-10-21 Bitdefender

https://www.youtube.com/watch?v=r-rChSE8-VA

Thumbnail for Fake Jobs, Real Malware. Uncovering How Cybercriminals are Exploiting the Employment Market

Lazarus Group used fake recruiter outreach on LinkedIn and other job platforms to lure developers into running malicious coding-assessment projects. The infection chain hid an obfuscated JavaScript loader and infostealer inside repositories copied from public code, then downloaded self-unpacking Python scripts and a later binary payload. The final stages expanded credential and data theft and communicated with command-and-control infrastructure through Tor, while public services such as Pastebin were used during the chain. The campaign matters because it turns routine developer hiring workflows into an execution path for malware, making social-engineering controls and code-review hygiene critical for organizations.

Related Actors

Related Reports

« Back