The Resume Trap: How ‘BlackSanta’ Malware Uses Fake CVs to Blind EDRs and Hijack HR Systems
ID: 14c7c99f-aa6d-5a97-97f2-28e939afc74c
STIX ID: report--14c7c99f-aa6d-5a97-97f2-28e939afc74c
Feed Name: securityonline.info
Aryaka Threat Labs describes the BlackSanta campaign — a sophisticated, Russian-speaking threat actor operation that weaponizes resume-themed ISO files delivered to HR/recruitment staff; the ISO contains a malicious .LNK that launches a multi-stage chain including an EDR-killer that uses Bring Your Own Driver techniques to neutralize antivirus/EDR, a steganographically hidden PowerShell loader, environment and locale checks to avoid CIS targets, and modules that steal cryptocurrency wallet artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
