Academic researchers are being targeted by a sophisticated cyber-attack that uses fake resumes to install malware on their computers. The attack involves a Windows executable hidden within an archive that seems to contain a graduate school application, while a legitimate Word document opens to distract the user.
Deceptive Resume Tactics
The attack masquerades as a job application from a supposed graduate of the Beijing Institute of Technology specializing in electrical engineering and applied AI. This targets professors and lab staff, exploiting academic correspondence as a means of infiltration.
Cybersecurity expert Himanshu Anand reported this strategy to Cyber Security News, highlighting the delivery of SNOWLIGHT and VShell remote-access trojans through a complex memory-based chain. Although the attack aims at research workstations, the identity and motives of the perpetrators remain unknown.
Technical Execution of the Attack
The malicious archive is labeled in Chinese, attributed to a fictitious graduate named Zhang Yuguang. It contains an executable disguised with a document-style name, leveraging Windows’ default setting to hide known file extensions.
Upon execution, the loader triggers the opening of a genuine DOCX resume, while checking the system’s environment and avoiding systems with fewer than four CPU cores. This method is specifically designed to deceive technical academics by claiming expertise in AI-based diagnostics and renewable energy systems.
Implications and Security Measures
SNOWLIGHT establishes remote access by contacting a command server, sending a system check-in, and receiving an encrypted payload, which is then decoded and run by VShell. Although the attack’s full scope was not observed, VShell’s capabilities include command execution and network exploration.
The use of academic themes in these attacks emphasizes the importance of cautious file handling by researchers and IT departments. Verifying unsolicited applications through alternative channels, enabling file extension visibility, and blocking unexpected executable content are crucial steps in mitigating such threats.
Similar scams have affected business sectors through fake resumes, indicating the widespread nature of this social engineering tactic. Security teams should monitor for unusual network activities and resume-themed files to preemptively address potential breaches.
Conclusion
The attack on academic researchers underscores the need for robust cybersecurity practices within educational institutions. As hackers increasingly exploit academic contexts, researchers and IT teams must remain vigilant and proactive in safeguarding their systems from such deceptive threats.
