APT Lures Shift to Jobs, Code Reviews, Cloud Apps

AhnLab ASEC · High sophistication
Last updated July 30, 2026

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and breach/security notifications) to trick targets into clicking links, opening files, or installing malicious packages. It highlights how attackers increasingly abuse trusted platforms (GitHub, Google Docs/Drive, npm, LinkedIn, Telegram, and cloud storage) to deliver malware or steal accounts and tokens.

How the attack worked

This threat trend report describes several unrelated APT campaigns that share a common thread: social engineering delivered through everyday professional channels rather than obvious spam. Attackers posed as recruiters on LinkedIn, requested code reviews or issued fake security advisories to developers, and built phishing pages that mimicked a widely used email service. Once a target clicked a link, opened a file, or signed into a spoofed page, the attackers moved to credential theft, remote access, or data exfiltration.

Why it succeeded

Each lure was built around an activity people do routinely at work. A developer reviewing code, a job seeker responding to a recruiter, or an employee logging into email are all normal actions, which makes the malicious version harder to spot at a glance. The report notes that North Korea linked actors exploited developer-friendly platforms such as GitHub, npm, VS Code, and Cursor, blending malicious content into tools developers already trust. Iran-linked Nimbus Manticore used fake LinkedIn recruiters and impersonated a real job portal, Ebix, adding a layer of apparent legitimacy to the outreach.

What to watch for

  • Unsolicited recruiter messages that quickly push a specific portal link or download
  • Code review or security advisory requests from unfamiliar senders, especially ones asking for repository sign-in or token entry
  • Login or "account verification" pages that don't quite match the real service, such as the phishing pages disguised as the 163 email service used by Bitter (APT-C-08)
  • Shared files or links through cloud storage services like Google Drive, Dropbox, pCloud, or Zoho WorkDrive that arrive without a clear business reason

Building resistance

Organizations across software development, cryptocurrency and financial services, government, defense, healthcare, energy, and telecommunications are all named as affected industries, showing how broadly these lures can reach. Developers and DevOps staff should verify code-review or advisory requests through a trusted channel before authenticating anywhere or running referenced code. HR, finance, and general staff should treat unexpected recruiter outreach and "security update" prompts with the same scrutiny as any unsolicited request for credentials. Because legitimate cloud services such as GitHub Releases, Google Drive, Dropbox, and pCloud were used for C2 communication and payload delivery, security teams should assume these platforms can be abused and build verification steps around any shared file or link, not just around unfamiliar domains. Techniques referenced in this report include spearphishing links (attack.mitre.org/techniques/T1566/002), spearphishing attachments (attack.mitre.org/techniques/T1566/001), and trusted relationship abuse (attack.mitre.org/techniques/T1199).

Key findings

  • North Korea–linked actors used developer platforms (GitHub, npm, VS Code) and social lures like job offers and code reviews to target developers and crypto professionals.
  • Iran-linked Nimbus Manticore used fake LinkedIn recruiters and impersonated a job portal (Ebix) as the lure.
  • India-linked activity included phishing sites/download pages disguised as a real email service (163) and attachments disguised as resumes.
  • Threat actors increasingly used legitimate cloud services (Drive/Dropbox/pCloud/Zoho WorkDrive) for payload delivery, command-and-control, or data theft.

Who’s being targeted

  • Commonly targeted roles: Developers, DevOps / Engineering, Information Security, HR / Recruiting, Finance, Executives, General employees.
  • Affected industries: Software developers / technology, Cryptocurrency / financial services, Information security, Government, Defense, Healthcare / medical research, Energy, Telecommunications.
  • Attack channels: linkedin, email, github, website.
  • Impersonated: Recruiter (fake) / Ebix job portal, Developer community / security advisory sender, 163 email service (spoofed).

Red flags to watch for

  • Unsolicited recruiter outreach pushing a link quickly
  • Pressure to use a specific portal/link rather than standard channels
  • Profile/portal details don’t match known company information
  • Unexpected code review request from an unknown sender
  • Link leads to a repo you don’t recognize or asks for sign-in/tokens
  • Unusual urgency tied to a vague “security advisory”
  • Login page URL/domain doesn’t match the real provider
  • Unexpected prompt to download a file to ‘verify’ access
  • Generic branding/typos on the page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What lures are APT groups using now?

Recent campaigns rely on job offers and fake recruiters, code review or security advisory requests, and phishing pages disguised as legitimate email services, according to the report.

Why are developer platforms like GitHub being targeted?

North Korea linked actors have exploited developer-friendly platforms such as GitHub, npm, VS Code, and GitLab, using social lures like job offers and code reviews to reach developers and crypto professionals.

How did Nimbus Manticore trick victims?

Nimbus Manticore lured victims using fake LinkedIn recruiters and by impersonating the Ebix job portal, then deployed data exfiltration and remote control capabilities.

What should employees watch for with cloud storage links?

Since legitimate cloud services such as GitHub Releases, Google Drive, Dropbox, and pCloud have been used for command and control and payload delivery, employees should confirm the sender and business reason before opening any shared file or link.

Read the video transcript

You get a LinkedIn message: “Hi, I’m recruiting for a role that matches your background. Please apply via the Ebix job portal link below.” Looks legit, right? Iran-linked Nimbus Manticore used fake LinkedIn recruiters and an Ebix lookalike site to get people to click, then deployed data theft and remote control tools, straight from that “job application” flow. Same playbook hits developers too: email says, “Subject: Code review request, please check this repo change ASAP.” You click a GitHub link, it wants you to sign in again or run a new package, perfect spot for North Korea–linked actors to steal tokens or slip in malicious code. Here’s the move: if a recruiter or code review request comes out of the blue and pushes a specific link, don’t click it, open the site yourself in a fresh tab and verify the job or repo from there.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026