Arab Security Consultants

  • Home
  • Courses
    • EC-Council Programs
    • EC-Council iWeek Courses
    • PECB
      • ISO/IEC 27001 Lead Implementer
      • ISO/IEC 27001 Lead Auditor
    • Cyber Book
  • Organized Events
    • Arab Security Conference
    • Arab Security Cyber WarGames
  • Services
    • CodeRed
    • OhPhish
    • Risk Assessment
    • Social Engineering
    • Identity & Access Security
    • Vulnerability Assessment
    • Penetration Testing
  • Training centers
  • EC-Council with ASC
  • News
  • Contact Us
  • Home
  • News
  • Microsoft Warns of Fake Skills Assessment Portals Targeting IT Job Seekers

Microsoft Warns of Fake Skills Assessment Portals Targeting IT Job Seekers

Microsoft Warns of Fake Skills Assessment Portals Targeting IT Job Seekers

by Ayman Hamam / Sunday, 12 November 2023 / Published in News

The well-known Lazarus Group has evolved, with a faction now setting up deceptive platforms masquerading as skill assessment portals, part of their new social engineering tactics. Identified by Microsoft as Sapphire Sleet, this alteration marks a change in the group’s persistent methods.

Sapphire Sleet, also recognized as APT38, BlueNoroff, CageyChameleon, and CryptoCore, is notorious for orchestrating cryptocurrency theft using social engineering techniques. Recently, Jamf Threat Labs connected this threat actor to ObjCShellz, a novel macOS malware associated with RustBucket, serving as a late-stage payload.

According to Microsoft’s Threat Intelligence team, Sapphire Sleet targets individuals through platforms like LinkedIn, using skill assessment-related bait before shifting communication to alternate platforms. Previously, the hacking crew utilized malicious attachments or embedded links in legitimate sites like GitHub, but recent swift detection led them to establish their network of websites for malware distribution.

These websites are designed to attract recruiters, prompting them to register for an account. Password protection hinders analysis and makes them a covert vehicle for malicious intent.

  • Tweet
Tagged under: Cyber Threats, Cybercrime, Cybersecurity Tactics, Hacker Techniques, Lazarus Group, macOS Malware, Malware Distribution, Sapphire Sleet, Social Engineering, Threat Actor

What you can read next

FBI’s Most-Wanted Zeus and IcedID Malware Mastermind Pleads Guilty
Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance
A Mexican hacker uses Android malware to attack global banks

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Home
  • Contact Us
  • Services
  • Training Centers
  • GET SOCIAL

Arab Security Consultants | Copyright © 2023 All rights reserved.

TOP