BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers

BatShadow, a Vietnamese threat actor, has been implicated in a recent operation that uses social engineering techniques to trick digital marketers and job seekers into downloading Vampire Bot, an as-yet-undiscovered piece of malware.

In a report shared with The Hacker News, researchers Aditya K. Sood and Varadharajan K. of Aryaka Threat Research Labs said that the attackers distribute infected files masquerading as job descriptions and company documents while posing as recruiters. These lures start a Go-based malware infection chain when they are opened.

According to the cybersecurity firm, the attack chains use ZIP archives that include malicious shortcuts (LNK) or executable files disguised as PDFs in order to fool users into opening the decoy PDF documents. The LNK file launches an embedded PowerShell script that connects to an external server and downloads a PDF for a Marriott marketing job.

Additionally, the PowerShell script downloads a ZIP file containing data for the remote desktop connection program XtraViewer from the same server and runs it read more about BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *