
Fake Resumes + Watering Holes Hit AnySign4PC Users
A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…
South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending password-protected ZIP “job offers” that infect devices when opened. In watering hole attacks, victims can be infected just by visiting a trusted site if their PC has vulnerable, unpatched security software installed.
South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses through two primary paths. The first is job-themed phishing, where attackers pose as job applicants sending a resume email with a link (instead of an attachment) pointing to a blog or GitHub page they control. A second variant impersonates an actual recruiter, sometimes hijacking a real headhunter's email account, and attaches a password-protected ZIP file labeled as a job offer that infects the machine the moment it's opened.
The second path is a watering hole attack. Attackers compromise legitimate sites people already trust, including news portals and hospital websites. Visiting the site alone can be enough to trigger an infection if the visitor's PC has an old, unpatched vulnerability in security software already installed, often software required for banking or government access.
These lures work because they exploit routine, expected behaviors. HR and hiring managers regularly review resumes and links from unfamiliar senders, and job seekers expect recruiter contact and attachments. The watering hole method is especially effective because no prompt appears, no warning shows up, the page looks completely normal, and the infection happens silently in the background. Victims have no reason to suspect anything went wrong, since the compromise happens on a site they already trust and use regularly.
Organizations and individuals can reduce exposure by treating job-application and recruiter emails as high-risk, verifying unfamiliar senders through an official channel before clicking links or opening attachments. Password-protected ZIP files tied to job offers deserve extra scrutiny or a safer review process rather than direct opening. Keeping security software updated is critical, since watering hole attacks can succeed without any user action if vulnerable software is present. Finally, turning on two-factor authentication and avoiding saved browser passwords limits the damage if credentials are ever exposed, since saved and manually typed credentials are a direct target of this activity.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They flagged two main initial-access paths: job-themed phishing emails (fake resumes and password-protected ZIP job offers) and watering hole attacks on compromised legitimate websites like news portals and hospital sites.
Yes, according to the advisory, visiting a compromised trusted site can be enough to trigger an infection if the visitor's PC has an old, unpatched vulnerability in installed security software, with no prompt or warning appearing.
Be wary of unsolicited resume emails that link to an external blog or GitHub page instead of a normal attachment, and treat password-protected ZIP job offers as high-risk even if they appear to come from a real recruiter.
The advisory recommends verifying unfamiliar senders through official channels before clicking links or opening attachments, turning on two-factor authentication, and avoiding saving passwords in the browser.
Right now in Korea, a state-backed group is going after companies using fake job emails and booby‑trapped websites. They pose as job applicants with a resume link to a blog or GitHub, or as recruiters sending a password‑protected ZIP 'job offer' that infects your PC the moment it’s opened. It gets worse: just visiting a trusted news or hospital site with old, unpatched security software can silently install malware that steals saved passwords, documents, and company data. Aha moment: any job email with a resume link or password‑protected ZIP is treat-as-hostile. Before you click or open, stop and verify the person through an official channel.

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The…