Hackers Exploit Job Search Websites to Deliver Malware via Resumes

Hackers are finding creative ways to breach businesses by exploiting job search websites, specifically CareerBuilder.com. They browse open positions and attach malicious documents as resumes in Microsoft Word format. When a resume is submitted, the platform generates a notification email to the job poster, attaching the document designed to deliver malware. This attack leverages the brand and service of a reputable site, increasing the likelihood of recipients opening and reading attachments, including malicious ones. The malicious document exploits a known Word vulnerability, dropping a rootkit on the victim's computer.

Key Takeaways:

  • Hackers are using job search websites like CareerBuilder.com to deliver malware via resumes in Microsoft Word format.
  • The attack exploits the brand and service of a real site, increasing the likelihood of recipients opening and reading attachments, including malicious ones.
  • The malicious document exploits a known Word vulnerability to place a binary that downloads and unzips an image file, dropping a rootkit on the victim's computer.
  • CareerBuilder has taken prompt action to address the issue after being alerted by Proofpoint researchers.
  • Owners of career websites that accept resumes should always assume content may be malicious and perform scanning prior to forwarding them to customers.
  • Job search websites beyond CareerBuilder.com are also susceptible to being exploited in this manner.
  • Attackers use the circulation of resumes within an organization to move laterally, enabling them to evade automated defenses and fool skeptical end-users.
  • This attack results in victims welcoming a piece of malware instead of a new employee.

Statistics:

  • The attackers exploit a known Word vulnerability to deliver malware.
  • The malicious document downloads and unzips an image file, which drops a rootkit on the victim's computer.
  • The attackers use the brand and service of a reputable site to increase the likelihood of recipients opening and reading attachments, including malicious ones.
  • CareerBuilder has taken prompt action to address the issue, but all job search websites are susceptible to similar exploitation.
  • Owners of career websites should perform scanning on resumes prior to forwarding them to customers to mitigate this threat.

Sources:

  • "Hackers Exploit Job Search Websites to Deliver Malware via Resumes" - Cyber Media (India) Ltd., distributed by Contify.com.
  • Proofpoint researchers, as cited in the text.