Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

FleetWorks raises $17 million to match truck drivers with freight faster

Aquawise unveils AI-powered water quality technology at TechCrunch Disrupt 2025

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Batshadow Group hunts job seekers using the new GO-based “Vampire Bot” malware
Identity

Batshadow Group hunts job seekers using the new GO-based “Vampire Bot” malware

userBy userOctober 7, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 7, 2025Ravi LakshmananMalware/Threat Intelligence

The Vietnamese threat actor named Batshadow is attributed to a new campaign that calls previously undocumented malware vampirebots, leveraging social engineering tactics to deceive job seekers and digital marketing experts.

“Attacks will pos as recruiters and distribute malicious files disguised as job descriptions and corporate documents,” Aryaka Threat Research Laborers researchers Aditya K Sood and Varadharajan K said in a report they share with Hacker News. “When opened, these lures cause infection strands of GO-based malware.”

The attack chain leverages a ZIP archive containing decoy PDF documents, according to cybersecurity companies, and opens users using malicious shortcuts (LNKs) or executables masked as PDFs. Upon booting, the LNK file runs an embedded PowerShell script that contacts an external server to download the Lure document, which is a PDF of the marketing job in Marriott.

PowerShell scripts can also be run from the same server to download zip files containing files related to Xtraviewer, the remote desktop connection software, and to establish permanent access to the compromised host.

DFIR Retainer Service

The victim clicking on the Lure PDF link and possibly “preview” the browser is not supported and is directed towards another landing page that provides a fake error message saying “The page only supports Microsoft Edge downloads.”

“When a user clicks the OK button, Chrome blocks redirects at the same time,” says Aryaka. “The page will then display another message asking the user to copy the URL and open it in the Edge Browser and download the file.”

For example, in contrast to Google Chrome and other web browsers, attacker instructions to get victims to use Edge are likely to lie in the fact that scripted pop-ups and redirects are likely to be blocked by default, whereas manually copy and paste the URL can continue the infection chain to be treated as the effect the user used.

However, if the victim chooses to open the page in Edge, the URL will be launched programmatically in a web browser and only to display the second error message “Online PDF viewer is currently experiencing problems. The file has been compressed and sent to the device.”

This will trigger an automatic download of a zip archive containing job descriptions, including a malicious executable (“marriott_marketing_job_description.pdf.exe”).

The executable is a Vampire bot called the Golang Malware Bot, which can profile infected hosts, steal a wide range of information, capture screenshots at configurable intervals, and maintain communication with attacker control servers (API3.Samsungcareers)[.]Task “) Run the command or get an additional payload.

The link to Vietnam for Bat Shadow is attributed to the use of IP addresses (103.124.95[.]161) It was previously flagged as hackers were used by hackers with links to the country. Additionally, digital marketing experts are one of the main targets of attacks carried out by various Vietnamese financially motivated groups, with a track record of deploying steeler malware to hijack Facebook business accounts.

CIS Build Kit

In October 2024, Cyble also revealed details of a sophisticated multi-stage attack campaign organized by Vietnamese threat actors who used Booby Rat to target job seekers and digital marketing experts.

Batshadow has been rated active for at least a year and uses similar domains such as Samsung-Work.com to propagate malware families including Agent Tesla, Lumma Stealer and Venom Rat.

“Bat Shadow threat groups continue to employ sophisticated social engineering tactics to target job seekers and digital marketing professionals,” Alyakah said. “By leveraging disguised documents and multi-stage infection chains, this group offers GO-based vampire bots that can monitor systems, data removal, and perform remote tasks.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleICE buys vehicles equipped with fake cell towers to monitor cell phones
Next Article Tesla unveils slightly cheaper ‘standard’ versions of Model 3 and Model Y
user
  • Website

Related Posts

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

October 14, 2025

How Threat Hunting Builds Readiness

October 14, 2025

A single 8-byte write shatters AMD’s SEV-SNP Confidential Computing security

October 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

FleetWorks raises $17 million to match truck drivers with freight faster

Aquawise unveils AI-powered water quality technology at TechCrunch Disrupt 2025

Instagram shows PG-13 content to teens by default, adds parental controls

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Beyond the Algorithm: How FySelf’s TwinH and Reinforcement Learning are Reshaping Future Education

Meet Your Digital Double: FySelf Unveils TwinH, the Future of Personalized Online Identity

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.