Cybercriminals use malware-laced CVs to steal banking credentials


Security researchers have discovered malicious files masquerading as CVs online that lure victims into giving up their banking passwords and other financial information.
According to Check Point, the malicious Microsoft Excel files were sent via email with subject lines such as “applying for a job” or “regarding job”. When victims open the attached files, they are asked to “enable content” and this allows for the ZLoader malware to be installed on their computers. This banking malware is designed to steal credentials and other private information from users of targeted financial institutions.
The malware also has the ability to steal any passwords and cookies stored in victim’s web browsers. Using this stolen information, cybercriminals can then connect to the victim’s system and make illicit financial transactions from the banking user’s legitimate device.
Check Point researchers have recently seen an increase in CV-themed scams in the US. During the past two months, the number of malicious files in CVs doubled with 1 out of 450 malicious files identified related to a CV file as cybercriminals try to exploit layoffs and remuneration schemes during the pandemic.
Malicious medical leave forms
In addition to CVs containing malicious files, Check Point researchers also found an increase in malicious medical leave forms circulating online.
The documents, which use names such as “COVID -19 FLMA Center.doc”, infect victims with the IcedID banking malware that targets banks, payment card providers, mobile service providers and e-commerce sites.
The aim of this malware is to try and trick users into submitting their credentials on a fake page as well as their authorization details that can be used to compromise user accounts. These malicious files were sent via email with the subject line “The following is a new Employee Request Form for leave within the Family and Medical Leave Act (FMLA)”. To lure victims into opening these forms, cybercriminals sent them from different sender domains like “medical-center.space”.
Manager of data intelligence at Check Point, Omer Dembinsky provided further insight on the findings of the company’s researchers, saying:
“As unemployment rises, cyber criminals are hard at work. They are using CVs to gain precious information, especially as it relates to money and banking. I strongly urge anyone opening an email with a CV attached to think twice. It very well could be something you regret.”
Security researchers have discovered malicious files masquerading as CVs online that lure victims into giving up their banking passwords and other financial information. According to Check Point, the malicious Microsoft Excel files were sent via email with subject lines such as “applying for a job” or “regarding job”. When victims…
Recent Posts
- Top digital loan firm security slip-up puts data of 36 million users at risk
- Nvidia admits some early RTX 5080 cards are missing ROPs, too
- I tried ChatGPT’s Dall-E 3 image generator and these 5 tips will help you get the most from your AI creations
- Gabby Petito murder documentary sparks viewer backlash after it uses fake AI voiceover
- The quirky Alarmo clock is no longer exclusive to Nintendo’s online store
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010