Sunday, 23 February 2025
26.8 C
Singapore
29.3 C
Thailand
19.9 C
Indonesia
25.5 C
Philippines

Beware: Cyber attackers target the aerospace sector with fake job offers

Cybersecurity experts have uncovered a malware campaign targeting aerospace, with fake job offers linked to Iranian hackers imitating North Korean tactics.

Cybersecurity experts warn that hackers linked to the Iranian government are deploying malware in the guise of job offers, aiming to infiltrate the aerospace sector. A recent report by ClearSky Cyber Security reveals how this Iranian state-sponsored group, known as TA455, is targeting employees in aerospace, defence, and government sectors, especially in the United States, Middle East, and Europe. This cyber-espionage operation, called โ€œDream Job,โ€ employs tactics that closely resemble those used by North Korean hacker groups, leaving researchers to speculate on possible collaboration or mimicry.

Hackers use fake job sites and profiles

ClearSky researchers have exposed the methods used by TA455 to deceive unsuspecting victims. The hackers set up fake recruitment websites and created fraudulent social media profiles, particularly on LinkedIn. These fake profiles are designed to lure targeted employees by offering enticing job opportunities.

Once the victim expresses interest, the hackers send job-related documents as part of the โ€œonboarding process.โ€ However, these documents carry a malicious file called SnailResin, a malware designed to breach the victimโ€™s systems. SnailResin is a loader for a secondary malware called SlugResin, which allows hackers to exfiltrate data, maintain remote system control, and ensure ongoing access even after detection attempts.

Iranian hackers may be mimicking North Korea’s Lazarus Group

ClearSky has found the tactics used in โ€œDream Jobโ€ strikingly similar to those previously attributed to Lazarus, a notorious North Korean hacking group. Lazarus is infamous for targeting individuals with fake job offers, especially in the cryptocurrency and tech sectors. The resemblance has led researchers to speculate whether TA455 is copying Lazarusโ€™s techniques to obscure its identity or whether the two groups might collaborate.

TA455, also known as Charming Kitten, shares traits with other Iranian cyber-espionage groups, such as APT35 and TA453. Linked to Iranโ€™s Islamic Revolutionary Guard Corps (IRGC), TA455 has a history of cyber-espionage in aerospace, defence, and government agencies. The group’s main objectives are to collect geopolitical intelligence and steal confidential information to be leveraged for strategic advantage.

ClearSkyโ€™s analysis suggests that TA455 deliberately impersonates Lazarusโ€™s style or that North Korean and Iranian groups share malware and tactics. Researchers have not reached a definitive conclusion but believe TA455 might use resemblance as a disguise.

Protect yourself from fake job offers

This โ€œDream Jobโ€ campaign serves as a timely reminder of the risks associated with unsolicited job offers, especially those from unfamiliar sources. The โ€œtoo good to be trueโ€ approach often indicates potential deception, as attackers increasingly use enticing offers to trick targets into unknowingly compromising their data security.

Experts recommend verifying the legitimacy of job offers and being cautious about downloading files, especially from unknown senders. If youโ€™re considering a job offer from an unfamiliar recruiter, take steps to authenticate the source and confirm their identity. Cybersecurity vigilance is key to protecting sensitive information from prying hackers.

Hot this week

Malaysia benefits as global chip supply shifts

Malaysiaโ€™s semiconductor industry benefits from US-China trade tensions, attracting investment due to its neutrality and strong government support.

American Airlines introduces AirTag location sharing for lost luggage

American Airlines now supports Appleโ€™s AirTag location sharing, making it easier for passengers to track and recover lost luggage.

‘TeslaTakeover’ protests continue to grow, albeit small in number

Protests continue to grow, targeting Tesla showrooms over Elon Muskโ€™s political actions, with more expected during the Presidentโ€™s Day holiday.

ASUS ZenScreen Duo OLED: A portable dual-screen setup for enhanced productivity

ASUS has launched the ZenScreen Duo OLED, a compact and lightweight dual-screen monitor designed for professionals and gamers on the go.

Singapore businesses embrace AI to boost efficiency

Singapore businesses and government agencies use AI to improve efficiency, reduce costs, and enhance productivity, as shared at Microsoftโ€™s AI Tour.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BTโ€™s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

The Vision Pro is now easier to share, and getting a new iPhone app

Appleโ€™s Vision 2.4 update makes sharing the Vision Pro easier, introduces a new iPhone app for content discovery, and adds the Spatial Gallery app.

Related Articles