logo

HR, recruiters targeted in year-long malware campaign

ID: 13d49f1a-fb85-5be2-bfed-54d88dca05ff

STIX ID: report--13d49f1a-fb85-5be2-bfed-54d88dca05ff

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

**Resume-themed ISO lure leads to stealthy EDR-killer campaign**: Researchers uncovered a low-noise, Russian-speaking threat actor using resume-themed ISO attachments to mount a multi-stage infection (PowerShell, steganography, DLL sideloading) that downloads a DWrite.dll component and a previously undocumented BlackSanta EDR killer; BlackSanta abuses vulnerable kernel drivers to neutralize endpoint detection and likely enables follow-on information-stealing payloads, while the actor deliberately avoids sandbox/analysis and excludes victims in Russia/CIS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.