Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers

Key Findings

  • Both chains open with a fake recruiter. A file that looks like a job description or an interview document arrives from someone posing as a hiring contact. One double-click is the only victim action either chain requires. Everything after that runs without further interaction.
  • Campaign 1 overlaps with a known Vietnam-nexus criminal cluster. The PureRAT command-and-control address and port recovered from this sample, 15[.]235[.]156[.]143 on 56001, match infrastructure that Cyble published in March 2026 for a PXA Stealer job-lure campaign. The loader filenames, the encoding stack, and the side-loading technique match as well. Howler Cell assesses with high confidence that Campaign 1 belongs to that activity cluster.
  • Campaign 2 has no public overlap. The implant is custom native code with its own infrastructure, its own operator portal, and no tooling in common with Campaign 1. The two campaigns converge on tradecraft, not on a shared operator. Howler Cell makes no attribution for Campaign 2.
  • Neither final payload touches disk. Campaign 1 runs a .NET Reactor-protected PureRAT implant through Donut shellcode. Campaign 2 reflectively maps a decrypted DLL into memory. File-based scanning has nothing to inspect at the point that matters.
  • Both blind Windows telemetry before the payload loads. AmsiScanBuffer and EtwEventWrite are patched or bypassed, so script scanning and .NET load events go dark ahead of execution. Campaign 1 does it twice, once ineffectively and once process-wide.
  • Both register persistence through the Task Scheduler COM interface. No schtasks.exe process is created, so the process-creation telemetry most scheduled-task detections key on never fires. Campaign 1 adds a WMI event subscription and a COM hijack on the MMDeviceEnumerator CLSID, then mirrors its staging directories so deleting one copy triggers a rebuild from the other.
  • Removing one artifact does not remove the infection. Campaign 1 runs three independent persistence mechanisms and two self-repairing staging directories. Partial remediation leaves a working implant behind.
  • Primary ATT&CK techniques: T1574.002 DLL side-loading, T1553.005 mark-of-the-web bypass, T1053.005 scheduled task, T1546.003 WMI event subscription, T1546.015 COM hijacking, T1562.001 and T1562.006 impair defenses, T1620 reflective code loading, T1497.001 and T1497.003 sandbox and time-based evasion, T1573.002 encrypted channel. Full mapping in Table 8.

Who Is Behind This 

Job-themed social engineering has become one of the most productive initial access routes in criminal operations, and it is worth being precise about why. A recruitment message arrives in a context the target has already decided to trust. Job seekers expect unsolicited outreach. They expect attachments. They expect to be asked to open a document before a call. The lure does not have to defeat suspicion because the target has already lowered it.

Article Link: Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers