• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hackers exploit job boards in apac, steal data of millions

Hackers Exploit Job Boards in APAC, Steal Data of Millions of Job Seekers

You are here: Home / General Cyber Security News / Hackers Exploit Job Boards in APAC, Steal Data of Millions of Job Seekers
February 6, 2024

Work businesses and retail organizations chiefly located in the Asia-Pacific (APAC) area have been targeted by a previously undocumented threat actor recognized as ResumeLooters because early 2023 with the aim of stealing delicate information.

Singapore-headquartered Group-IB explained the hacking crew’s activities are geared in direction of job search platforms and the theft of resumes, with as a lot of as 65 sites compromised concerning November 2023 and December 2023.

The stolen data files are estimated to include 2,188,444 person knowledge data, of which 510,259 have been taken from career lookup sites. More than two million unique email addresses are present in the dataset.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“By using SQL injection attacks towards internet sites, the threat actor attempts to steal consumer databases that might involve names, phone numbers, emails, and DoBs, as nicely as information and facts about work seekers’ working experience, work background, and other delicate own data,” security researcher Nikita Rostovcev explained in a report shared with The Hacker Information.

Cybersecurity

“The stolen details is then put up for sale by the threat actor in Telegram channels.”

Team-IB claimed it also uncovered evidence of cross-web page scripting (XSS) bacterial infections on at minimum 4 respectable career search websites that are built to load malicious scripts accountable for displaying phishing pages able of harvesting administrator credentials.

ResumeLooters is the 2nd group just after GambleForce that has been discovered staging SQL injection attacks in the APAC location since late December 2023.

Job Seekers

A majority of the compromised web-sites are dependent in India, Taiwan, Thailand, Vietnam, China, Australia, and Turkey, though compromises have also been noted from Brazil, the U.S., Turkey, Russia, Mexico, and Italy.

The modus operandi of ResumeLooters entails the use of the open-source sqlmap resource to have out SQL injection attacks and drop and execute more payloads these as the BeEF (shorter for Browser Exploitation Framework) penetration testing instrument and rogue JavaScript code built to obtain sensitive data and redirect end users to credential harvesting web pages.

The cybersecurity company’s examination of the danger actor’s infrastructure reveals the presence of other applications like Metasploit, dirsearch, and xray, together with a folder hosting the pilfered facts.

Cybersecurity

The marketing campaign seems to be financially determined, presented the point that ResumeLooters have established up two Telegram channels named 渗透数据中心 and 万国数据阿力 last 12 months to provide the details.

“ResumeLooters is nevertheless a different illustration of how a great deal injury can be produced with just a handful of publicly accessible resources,” Rostovcev claimed. “These attacks are fueled by poor security as perfectly as insufficient databases and web-site administration practices.”

“It is hanging to see how some of the oldest but remarkably efficient SQL attacks continue to be prevalent in the region. On the other hand, the tenacity of the ResumeLooters team stands out as they experiment with numerous approaches of exploiting vulnerabilities, including XSS attacks.”

Uncovered this report interesting? Observe us on Twitter  and LinkedIn to browse a lot more unique content material we article.


Some areas of this posting are sourced from:
thehackernews.com

Previous Post: «recent ssrf flaw in ivanti vpn products undergoes mass exploitation Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation
Next Post: How a $10B Enterprise Customer Drastically Increased their SaaS Security Posture with 201% ROI by Using SSPM how a $10b enterprise customer drastically increased their saas security»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets
  • Over 269,000 Websites Infected with JSFireTruck JavaScript Malware in One Month
  • Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion
  • CTEM is the New SOC: Shifting from Monitoring Alerts to Measuring Risk
  • Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware
  • WordPress Sites Turned Weapon: How VexTrio and Affiliates Run a Global Scam Network
  • New TokenBreak Attack Bypasses AI Moderation with Single-Character Text Changes
  • AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar
  • Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction
  • Non-Human Identities: How to Address the Expanding Security Risk

Copyright © TheCyberSecurity.News, All Rights Reserved.