Nov 15, 2024 | Iranian threat group TA455 is using fake job offers to infiltrate the aerospace industry, according to ClearSky Cyber Security. The campaign distributes SnailResin malware, leading to SlugResin backdoor infections.
Victims are lured via deceptive LinkedIn profiles and job-related ZIP files containing malicious executables. TA455 blends legitimate traffic from platforms like GitHub and Cloudflare to evade detection. This sophisticated operation raises concerns about potential collaboration between Iranian and North Korean APT groups, given overlapping tactics.
Thanks for signing up!