Sandworm has turned the routine job interview into a route for compromising IT workers. The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network client to reach people who may hold privileged access to company systems. The operation targets system administrators and other IT specialists after attackers study their resumes on job-search sites. It begins with a message from a supposed employer, moves into a chat and then presents a technical assessment that appears to need a corporate VPN connection. CERT-UA analysts identified the activity as UAC-0145, a Sandworm-linked subcluster also known as APT44 and Seashell Blizzard. The agency said the activity has continued...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!