logo

Fake job applications pack malware that kills EDR before stealing data

ID: 62ea1229-2e14-5c59-8b9a-71b9df3fea3d

STIX ID: report--62ea1229-2e14-5c59-8b9a-71b9df3fea3d

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-03-10

Date Updated: 2026-04-26

Author: Carly Page

...
...

A Russian-speaking cybercriminal campaign targets HR teams by sending what appear to be legitimate CVs hosted on cloud storage; when opened the ISO mounts and a shortcut executes hidden commands that unpack malware hidden in an image. The payload, dubbed "BlackSanta," uses Bring Your Own Vulnerable Driver (BYOVD) techniques to obtain kernel-level access, disable antivirus/EDR and logging, then collect and exfiltrate sensitive files and cryptocurrency artifacts, highlighting recruitment workflows as an effective attack vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.