Get a Pentest and security assessment of your IT network.

News

CareerBuilder listings used as Phishing platform

Researchers at Proofpoint discovered a Phishing campaign that originated form select job postings on CareerBuilder. The attack starts by submitting a malicious Word document (named resume.doc or cv.doc) to a job posting. The malicious Word files that were sent are also another point of technicality. They exploited a known vulnerability (e.g. CVE-2014-1761 or CVE-2012-0158) In this case, once the document is opened, the exploited vulnerability will place a binary on the system that downloads and unzips an image file, which in turn installs the Sheldor rootkit.”]

Source: https://www.csoonline.com/article/2916524/careerbuilder-listings-used-as-phishing-platform.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2