Saturday, 18 January 2025
25.4 C
Singapore

Beware: Cyber attackers target the aerospace sector with fake job offers

Cybersecurity experts have uncovered a malware campaign targeting aerospace, with fake job offers linked to Iranian hackers imitating North Korean tactics.

Cybersecurity experts warn that hackers linked to the Iranian government are deploying malware in the guise of job offers, aiming to infiltrate the aerospace sector. A recent report by ClearSky Cyber Security reveals how this Iranian state-sponsored group, known as TA455, is targeting employees in aerospace, defence, and government sectors, especially in the United States, Middle East, and Europe. This cyber-espionage operation, called “Dream Job,” employs tactics that closely resemble those used by North Korean hacker groups, leaving researchers to speculate on possible collaboration or mimicry.

Hackers use fake job sites and profiles

ClearSky researchers have exposed the methods used by TA455 to deceive unsuspecting victims. The hackers set up fake recruitment websites and created fraudulent social media profiles, particularly on LinkedIn. These fake profiles are designed to lure targeted employees by offering enticing job opportunities.

Once the victim expresses interest, the hackers send job-related documents as part of the “onboarding process.” However, these documents carry a malicious file called SnailResin, a malware designed to breach the victim’s systems. SnailResin is a loader for a secondary malware called SlugResin, which allows hackers to exfiltrate data, maintain remote system control, and ensure ongoing access even after detection attempts.

Iranian hackers may be mimicking North Korea’s Lazarus Group

ClearSky has found the tactics used in “Dream Job” strikingly similar to those previously attributed to Lazarus, a notorious North Korean hacking group. Lazarus is infamous for targeting individuals with fake job offers, especially in the cryptocurrency and tech sectors. The resemblance has led researchers to speculate whether TA455 is copying Lazarus’s techniques to obscure its identity or whether the two groups might collaborate.

TA455, also known as Charming Kitten, shares traits with other Iranian cyber-espionage groups, such as APT35 and TA453. Linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), TA455 has a history of cyber-espionage in aerospace, defence, and government agencies. The group’s main objectives are to collect geopolitical intelligence and steal confidential information to be leveraged for strategic advantage.

ClearSky’s analysis suggests that TA455 deliberately impersonates Lazarus’s style or that North Korean and Iranian groups share malware and tactics. Researchers have not reached a definitive conclusion but believe TA455 might use resemblance as a disguise.

Protect yourself from fake job offers

This “Dream Job” campaign serves as a timely reminder of the risks associated with unsolicited job offers, especially those from unfamiliar sources. The “too good to be true” approach often indicates potential deception, as attackers increasingly use enticing offers to trick targets into unknowingly compromising their data security.

Experts recommend verifying the legitimacy of job offers and being cautious about downloading files, especially from unknown senders. If you’re considering a job offer from an unfamiliar recruiter, take steps to authenticate the source and confirm their identity. Cybersecurity vigilance is key to protecting sensitive information from prying hackers.

Hot this week

AI-driven data growth to boost demand for cloud storage, says Seagate survey

AI adoption drives data storage growth, with 53% of Singapore firms expecting cloud storage needs to double by 2028, says Seagate survey.

Apple’s sleek iPhone 17 Air is expected to launch this autumn

Apple’s iPhone 17 Air, a slim model launching this autumn, may feature future techs like foldable-ready design, in-house modems, and AI advancements.

Will there be a Black Myth: Wukong 2?

Black Myth: Wukong 2 isn’t confirmed, but Game Science hints at DLC, future mythological heroes, and an expanding Black Myth universe.

Xiaomi launches Redmi Note 14 series in Singapore with pro-grade photography and robust durability

Xiaomi unveils the Redmi Note 14 series in Singapore with flagship-level cameras, durability, and high performance at accessible prices.

Samsung Galaxy S25 colours leak ahead of launch

Samsung Galaxy S25 leaks reveal eight stunning colours and confirm Galaxy Unpacked on January 22. Full details on models, shades, and more.

Samsung Galaxy S25 Slim: What you need to know

Discover the 6.4-mm-thin Samsung Galaxy S25 Slim, which will launch in May 2024. It features triple cameras and a Snapdragon 8 Elite processor.

Asus ProArt Display 5K delivers stunning visuals and exceptional accuracy

ASUS launches the ProArt Display 5K PA27JCV in Singapore, which costs S$1,099 and offers precision colour accuracy, HDR support, and LuxPixel tech.

OPPO partners with football prodigy Lamine Yamal as global ambassador

OPPO announces Lamine Yamal as global ambassador, combining football and technology to inspire young people through the "Make Your Moment" campaign.

DXC and Ferrari join forces for next-gen vehicle technology

DXC partners with Ferrari to create next-gen infotainment systems, including the F80’s advanced digital cockpit for road and track use.

Related Articles

Popular Categories