Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use Fake Job Portals to Spread Malware

Hackers Use Fake Job Portals to Spread Malware

Posted on June 2, 2026 By CWS

A hacking group linked to state actors has been exposed for conducting a deceptive recruitment scheme aimed at spreading specialized malware. The group, identified as Nimbus Manticore, also known as UNC1549 and Smoke Sandstorm, has previously targeted professionals in the aerospace and defense industries across the Middle East and Europe.

Their recent operation underscores an increased level of technical complexity, marrying social engineering with a multi-layered malware distribution strategy that is difficult to uncover.

Deceptive Recruitment Strategy

Initially, the attackers reached out to potential victims on LinkedIn, posing as recruiters for Ebix, a legitimate company in the insurance and banking technology sector. They offered enticing salaries of up to $200,000 to lure victims.

Unsuspecting individuals were directed to a seemingly authentic hiring portal at ebix[.]recruitment-flow[.]com, where they were asked to enter their credentials before being exposed to harmful software.

Advanced Sideloading Techniques

During a recent incident response, Nextron analysts discovered this complex sideloading attack, linking it to Nimbus Manticore. The group maintains consistent tactics across campaigns, even as their tools and payloads evolve.

Upon logging into the counterfeit portal, victims were prompted to download what appeared to be a two-factor authentication app. This app, delivered in a ZIP file, contained the malware disguised as a Microsoft Visual Studio component named setup.exe, which was signed by Microsoft.

Persistence and Evasion Methods

The malware established persistence by creating a scheduled task called “BackupCheck,” ensuring its activation during every login. The payload, disguised as main.dll, communicated with command-and-control servers hosted on Microsoft Azure, making it difficult to detect.

The threat actors employed anti-analysis techniques, including inspecting process names and checking for active debuggers, to evade detection. Despite increased obfuscation, their core functions remained consistent with previous operations.

Protective Measures for Organizations

Organizations can mitigate exposure to such threats by blocking or restricting access to newly registered domains, especially in sensitive departments like HR and finance. Implementing Windows AppLocker to block execution from directories like AppData can also reduce risks.

Additionally, expanding security training to include awareness of social media and job portal-based attacks can help organizations defend against this sophisticated tactic employed by Nimbus Manticore.

For more updates on cybersecurity threats, follow us on Google News, LinkedIn, and X, and set CSN as a preferred source on Google.

Cyber Security News Tags:AppDomain hijacking, APT, cyber attack, Cybersecurity, Ebix impersonation, fake job portals, LinkedIn scam, Malware, Nimbus Manticore, social engineering

Post navigation

Previous Post: Dashlane Faces Brute-Force Attack, Limited Data Affected
Next Post: Red Hat NPM Packages Targeted in Supply Chain Breach

Related Posts

Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials Cyber Security News
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Cyber Security News
Cavalry Werewolf APT Hackers Attacking Multiple Industries With FoalShell and StallionRAT Cavalry Werewolf APT Hackers Attacking Multiple Industries With FoalShell and StallionRAT Cyber Security News
IBM Urges Immediate Patch for Identity Access Vulnerabilities IBM Urges Immediate Patch for Identity Access Vulnerabilities Cyber Security News
Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks Cyber Security News
Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • HP VoIP Phones Vulnerability Threatens Enterprise Security
  • Oracle WebLogic Vulnerability Exploited: CISA Issues Alert
  • Diverging Reports Address Cybersecurity Challenges
  • Halo Security’s Platform Wins Top MSP Award Again
  • Latest Android Update Fixes Zero-Day and 123 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • HP VoIP Phones Vulnerability Threatens Enterprise Security
  • Oracle WebLogic Vulnerability Exploited: CISA Issues Alert
  • Diverging Reports Address Cybersecurity Challenges
  • Halo Security’s Platform Wins Top MSP Award Again
  • Latest Android Update Fixes Zero-Day and 123 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark