Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use Fake Job Portals to Spread Malware

Hackers Use Fake Job Portals to Spread Malware

Posted on June 2, 2026 By CWS

A hacking group linked to state actors has been exposed for conducting a deceptive recruitment scheme aimed at spreading specialized malware. The group, identified as Nimbus Manticore, also known as UNC1549 and Smoke Sandstorm, has previously targeted professionals in the aerospace and defense industries across the Middle East and Europe.

Their recent operation underscores an increased level of technical complexity, marrying social engineering with a multi-layered malware distribution strategy that is difficult to uncover.

Deceptive Recruitment Strategy

Initially, the attackers reached out to potential victims on LinkedIn, posing as recruiters for Ebix, a legitimate company in the insurance and banking technology sector. They offered enticing salaries of up to $200,000 to lure victims.

Unsuspecting individuals were directed to a seemingly authentic hiring portal at ebix[.]recruitment-flow[.]com, where they were asked to enter their credentials before being exposed to harmful software.

Advanced Sideloading Techniques

During a recent incident response, Nextron analysts discovered this complex sideloading attack, linking it to Nimbus Manticore. The group maintains consistent tactics across campaigns, even as their tools and payloads evolve.

Upon logging into the counterfeit portal, victims were prompted to download what appeared to be a two-factor authentication app. This app, delivered in a ZIP file, contained the malware disguised as a Microsoft Visual Studio component named setup.exe, which was signed by Microsoft.

Persistence and Evasion Methods

The malware established persistence by creating a scheduled task called “BackupCheck,” ensuring its activation during every login. The payload, disguised as main.dll, communicated with command-and-control servers hosted on Microsoft Azure, making it difficult to detect.

The threat actors employed anti-analysis techniques, including inspecting process names and checking for active debuggers, to evade detection. Despite increased obfuscation, their core functions remained consistent with previous operations.

Protective Measures for Organizations

Organizations can mitigate exposure to such threats by blocking or restricting access to newly registered domains, especially in sensitive departments like HR and finance. Implementing Windows AppLocker to block execution from directories like AppData can also reduce risks.

Additionally, expanding security training to include awareness of social media and job portal-based attacks can help organizations defend against this sophisticated tactic employed by Nimbus Manticore.

For more updates on cybersecurity threats, follow us on Google News, LinkedIn, and X, and set CSN as a preferred source on Google.

Cyber Security News Tags:AppDomain hijacking, APT, cyber attack, Cybersecurity, Ebix impersonation, fake job portals, LinkedIn scam, Malware, Nimbus Manticore, social engineering

Post navigation

Previous Post: Dashlane Faces Brute-Force Attack, Limited Data Affected
Next Post: Red Hat NPM Packages Targeted in Supply Chain Breach

Related Posts

AliExpress Employs WebAudio for Device Fingerprinting AliExpress Employs WebAudio for Device Fingerprinting Cyber Security News
macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC Cyber Security News
Exploit Targets Windows Snipping Tool Vulnerability Exploit Targets Windows Snipping Tool Vulnerability Cyber Security News
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data Cyber Security News
MCP Servers Found with Thousands of Security Flaws MCP Servers Found with Thousands of Security Flaws Cyber Security News
SAP Security Patch Day – 15 Vulnerabilities Patched including 3 Critical Injection Vulnerabilities SAP Security Patch Day – 15 Vulnerabilities Patched including 3 Critical Injection Vulnerabilities Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Exploits in Langflow and Rails Impact Global Systems
  • Hackers Launch Password-Spraying Assault on AWS Accounts
  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Exploits in Langflow and Rails Impact Global Systems
  • Hackers Launch Password-Spraying Assault on AWS Accounts
  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark