Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
FIN6 has been observed posing as job seekers to target recruiters with malicious resume links and downloads. The campaign reverses the usual job-scam pattern: instead of impersonating a recruiter to defraud an applicant, the attacker impersonates a candidate to compromise the recruiter’s device and potentially gain access to business systems.
Reporting from Mandiant and DomainTools describes fake resume websites, selective traffic filtering, CAPTCHA challenges, archives, disguised Windows shortcut files and the More_eggs backdoor. The public reporting documents activity in 2023 and a related DomainTools analysis published June 10, 2025; it does not establish how many victims there were or that every intrusion led to ransomware.
What FIN6’s fake-resume attack does
DomainTools identifies Skeleton Spider as FIN6, a financially motivated cybercrime group historically associated with payment-card theft and later enterprise intrusion activity. The observed campaign uses employment platforms such as LinkedIn and Indeed as communication surfaces. There is no indication in the cited reporting that those platforms themselves were breached.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →The supposed candidate builds credibility, contacts a recruiter and directs the recipient to a personal-looking resume or portfolio website. The resume is mainly a social-engineering lure. The real danger may be the website, archive, shortcut or script used to deliver malware.
#1 Best Overall
A reported attack chain can be summarized as:
Recruiter contact → rapport-building → resume domain → filtering or CAPTCHA → download → archive or shortcut → script execution → More_eggs → credential theft or follow-on access
This is a synthesis of reported variants, not a universal sequence. Mandiant documented an October 2023 operation involving LinkedIn, HR recruiters, a fake resume website and a PDF download. DomainTools later described a CAPTCHA-gated ZIP archive containing a malicious Windows shortcut file. The delivery format may change while the recruiter-focused social engineering remains consistent.
How the attack unfolds
1. Contact through a trusted hiring channel
The attacker approaches recruiters as a job seeker through a professional employment platform. The business context makes an unsolicited message seem ordinary: recruiters routinely receive candidate profiles, portfolios and resume links.
A legitimate-looking profile is not proof of identity. It could be fabricated, compromised or used only to establish enough trust for the next step.
2. Professionally written communication
The messages described by DomainTools were polished and tailored to recruiting workflows. Poor grammar is therefore not a dependable detection signal. A well-written message can still be a malware lure.
3. A manually typed URL
Rather than sending a clickable hyperlink, the supposed candidate may ask the recruiter to type a domain manually. This can reduce the effectiveness of some automated link-scanning controls, but it does not make the destination safe.
DNS security, secure web gateways, browser isolation, endpoint telemetry and domain-reputation controls can still provide protection. Manual entry is simply a way to avoid some layers of inspection.
4. A convincing resume page
The domains reportedly resemble personal websites and may combine a first and last name. Historical examples cited by DomainTools include:
bobbyweisman[.]comemersonkelly[.]comdavidlesnick[.]comkimberlykamara[.]comannalanyi[.]combobbybradley[.]netmalenebutler[.]comlorinash[.]comalanpower[.]netedwarddhall[.]com
These are historical indicators, not proof that every similarly named domain is malicious. Do not visit them. A single-page portfolio with little independent evidence of the candidate is a warning sign, but the page’s appearance alone cannot establish safety.
5. Selective delivery and CAPTCHA
DomainTools reported filtering based on factors including apparent geography, IP reputation, residential or cloud-hosted address space, operating system, browser characteristics and user-agent strings. CAPTCHA completion may precede the download.
Visitors who do not match the expected profile may receive a harmless page, plain-text resume or error. Consequently, a cloud sandbox, VPN or researcher may fail to reproduce the malicious behavior. That result does not prove the site is clean; selective delivery is part of the evasion technique.
CAPTCHA is also not a trust certificate. Attackers can use it to frustrate automated analysis and make a malicious page look more legitimate.
Rank #3
6. Archive and shortcut delivery
In the DomainTools-described variant, the download was a ZIP archive containing a disguised .LNK Windows shortcut. A shortcut can have a resume-like filename or icon while launching commands or scripts instead of displaying a document.
Windows may hide file extensions, and an archive can conceal the actual file type. Treat the following as executable content rather than ordinary documents when received unexpectedly:
.LNKand.SCR.JS,.VBSand.HTA.ISOand.IMG- Executable files and suspicious scripts
7. Script execution and More_eggs
DomainTools described the shortcut launching hidden JavaScript through wscript.exe, followed by connections to external resources and delivery of the More_eggs backdoor. Reported behaviors also include possible persistence through registry Run keys or scheduled tasks and the use of legitimate Windows utilities.
Recommended Free Tools
More_eggs is a JavaScript-based backdoor associated with the Golden Chickens/Venom Spider malware-as-a-service ecosystem. In this reported campaign, it could support credential theft, system access and follow-on payload delivery. That does not mean every recruiter compromise resulted in ransomware, data theft or a confirmed breach of a named victim.
Why recruiters are attractive targets
The technique abuses a legitimate business process rather than relying on an obviously suspicious invoice or password-reset message. Recruiters may:
- Receive frequent unsolicited applications and attachments.
- Communicate across email, LinkedIn, Indeed and other external platforms.
- Work under hiring deadlines that encourage quick decisions.
- Use laptops connected to email, applicant-tracking systems, directories and collaboration tools.
- Receive less malware-handling training than IT or finance personnel.
These are operational risk factors, not a claim that every recruiter has broad administrative access. The impact depends on the device, identity permissions, network segmentation and follow-on activity.
Rank #4
Red flags recruiters should recognize
- The candidate insists on a personal domain instead of using the organization’s applicant-tracking system.
- The domain is a newly created, name-based portfolio site with no independent employment history.
- The message asks you to type a URL manually.
- The website requires CAPTCHA before revealing a resume.
- The resume arrives as a ZIP archive.
- An archive contains a shortcut, script, disk image or executable file.
- The filename or icon resembles a PDF but the actual extension is different.
- The profile, email address, work history and resume contain inconsistencies.
- The sender pressures you to open the material immediately.
- The site contains little more than one resume and has no credible external presence.
Indeed separately recommends checking for inconsistent information, suspicious email addresses and generic resumes, and provides guidance for reporting suspicious applicants. See Indeed’s employer guidance.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →What recruiters should do
- Do not type or open the supplied domain. Ask the candidate to submit materials through the organization’s normal hiring system.
- Verify independently. Use established hiring records or a trusted contact method, not only details supplied in the suspicious message.
- Never open an unsolicited ZIP or shortcut on a production workstation.
- Preserve and report. Send the message, profile details, original headers and URLs to security staff, and report the account or message to LinkedIn or Indeed.
- Escalate immediately if anything was opened. Follow the organization’s incident-response process rather than attempting to investigate or clean the device yourself.
Controls security teams should prioritize
Block dangerous file types
Quarantine external archives containing .LNK, script and executable files. Where feasible, prevent shortcut execution from downloaded archives and common user-writable directories.
Monitor script and signed-binary abuse
Alert on unexpected execution of wscript.exe, cscript.exe, PowerShell, mshta.exe, regsvr32.exe, msxsl.exe and similar utilities. Pay particular attention when browsers, email clients, archive tools or explorer.exe spawn them.
Correlate multiple telemetry sources
Use email, DNS, secure-web-gateway, browser, endpoint and identity-provider logs together. A manually typed URL may evade clickable-link inspection, while selective delivery may evade a cloud scanner. Correlation can reveal the sequence even when no single control sees every stage.
Protect identities and limit blast radius
- Require phishing-resistant MFA for email, VPN, administrative tools and other high-value systems.
- Restrict recruiter workstations from unnecessary administrative resources.
- Maintain a fast reporting route for HR and recruiting staff.
- Hunt for unfamiliar registry Run keys and scheduled tasks after suspicious shortcut execution.
DomainTools specifically recommends blocking LNK execution from untrusted ZIP archives, detecting unexpected scripting-engine and living-off-the-land activity, and monitoring suspicious domains and persistence locations. Read the DomainTools analysis for the technical details.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If someone visited the site
If the recruiter only visited the page and did not open a file:
Best Value
- Record the complete URL, time, browser and device.
- Preserve the message and profile information.
- Check browser downloads, DNS records, proxy logs and endpoint telemetry.
- Look for unexpected authentication prompts, downloads or browser extensions.
- Report the domain to security operations and the relevant platform.
If someone opened the ZIP or shortcut
Treat the event as a potential compromise, not a near miss.
- Isolate the endpoint using the approved organizational process. Do not power it off unless incident responders direct you to do so, because volatile evidence may matter.
- Contact IT or security immediately and preserve the original email, archive, shortcut, scripts, hashes, URLs, DNS records and endpoint timeline.
- From a known-clean device, reset potentially exposed passwords, prioritizing email, VPN, cloud, privileged and applicant-tracking accounts.
- Revoke active sessions and refresh tokens where supported.
- Review identity logs for unusual logins, MFA changes, mailbox rules, OAuth grants and impossible-travel activity.
- Hunt for child processes from browsers, email clients, archive utilities or
explorer.exe, along with script interpreters, scheduled tasks, registry Run keys and suspicious outbound connections. - Determine whether the endpoint accessed internal file shares or sensitive HR systems.
If credentials were entered, reset them from a clean device, revoke sessions and tokens, inspect mailbox forwarding rules and authorized applications, review MFA recovery changes and check whether the password was reused elsewhere.
What this campaign does—and does not—show
The reports support a clear conclusion: recruiters can be targeted through ordinary hiring conversations, and fake resumes can be malware-delivery mechanisms. They do not establish a universal payload sequence, a specific victim count or ransomware in every incident.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsThe use of AWS-hosted infrastructure likewise does not mean AWS was compromised or is inherently unsafe. Attackers can abuse legitimate cloud services such as EC2, S3 or CloudFront-style infrastructure for disposable or selectively delivered content. Blocking an entire cloud provider is usually less useful than detecting suspicious domains, file behavior and endpoint execution.
For background, compare Mandiant’s M-Trends 2024 reporting with the later DomainTools analysis. The durable lesson is not to memorize one domain or file type. It is to make candidate materials flow through a controlled hiring process and treat unexpected downloads as potential security events.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

