Skip to main content

We use Google Analytics on Knowledge Center pages to understand aggregate readership. No account, session, or security-tool data is included. See our Privacy Policy.

CyberBlink AIEvidence. Clarity. Confidence.
Verified Incident

The Fake Recruiter: When a Dream Job Becomes a Cyberattack

A tailored job offer, sent by a recruiter who was never hiring at all. A documented 2024 espionage campaign shows how a real posting, a password-protected attachment, and one 'special reader' were enough to install a backdoor.

A job offer can arrive at exactly the right moment. The salary is strong, the company is real, and someone reached out to you specifically, based on your own background. That combination — flattering, specific, and well timed — is also the exact setup behind one of the more effective espionage campaigns documented in recent years.

The targets were not people scrolling job boards looking for work. They were working professionals already employed at real energy, aerospace, and defense-related companies, chosen because of the access their jobs already gave them, not because they were careless. And the 'recruiter' who contacted them was never hiring for anything at all.

EVIDENCEGoogle's Mandiant threat intelligence team has tracked UNC2970 across multiple campaigns involving job-themed social engineering. In a campaign detailed publicly in Mandiant's September 17, 2024 report, 'An Offer You Can Refuse,' UNC2970 approached senior employees at energy, aerospace, and nuclear-sector organizations across several countries over WhatsApp and personal email, posing as recruiters. One documented lure took a real, publicly posted BAE Systems job listing for a Vice President of Business Development and quietly edited it to match a specific target's own qualifications, then sent it inside a password-protected file. Opening the attached job description required a 'special PDF reader' the sender also provided — a modified copy of a legitimate, open-source PDF viewer. That modified reader displayed the document normally while quietly installing a backdoor Mandiant named MISTPEN, giving the attackers ongoing access to the victim's computer.
Illustrative reconstruction — a real posting, edited to fit, sent through a personal channel
01What Happened

Across documented UNC2970 campaigns, attackers have approached targets through recruiter personas, including professional networking platforms, email and WhatsApp — outside any system an employer's security team could see. The job description that followed looked legitimate because much of it was: the attackers reused real postings from real companies, editing only the details needed to fit the target.

The trap was the reader app packaged alongside the file. Because the attachment was encrypted, opening it required the tool the sender provided. Victims who ran it saw exactly what they expected — an ordinary job description on screen. In the background, the same program quietly loaded a backdoor and set up a scheduled task, so it kept running every time the computer restarted.

02Why It Matters

Nothing about this campaign relied on breaking into a company's network or exploiting a software flaw. The 'special reader' had no vulnerability in it at all — it was a working copy of a real program, quietly modified. The entire attack depended on one person trusting a message and running one file.

That is worth taking seriously even outside energy or defense work. UNC2970 targeted senior, well-connected employees specifically because of the systems and information their roles already touched, and researchers observed the group refining the same technique across more than one campaign. A convincing job offer is one of the few messages almost anyone will open without hesitation — which is exactly why it keeps getting reused.

Illustrative reconstruction — the document opened normally; that was the point
03How You Can Protect Yourself

None of this required a mistake anyone should feel embarrassed about — it required an unfamiliar verification habit. A few habits close the gap:

  • Be suspicious if an unsolicited recruiter requires you to install a new reader, viewer, or application just to open a job description. Verify the recruiter and role independently before installing anything.
  • Move any recruiting conversation off WhatsApp or personal email and onto the company's own hiring platform before sharing anything further.
  • Treat a password-protected attachment from an unsolicited contact as a red flag on its own, regardless of how relevant the role sounds.
  • Verify the opportunity directly on the company's own site before responding again, rather than through any link the message provides.

The verification step is short enough to remember under pressure: New Tab → Official Website → Careers → Verify. If the role isn't listed on the company's official careers site, verify it directly with the company through an independently obtained contact before proceeding.

Illustrative reconstruction — the same four steps, every time

General Guidance

CyberBlink Golden Rule: If an unsolicited job offer requires you to install unfamiliar software before you can even review the opportunity, stop and verify the recruiter and role independently first.

A common mistake

It is tempting to assume campaigns like this only threaten IT staff or executives. UNC2970's targets were business-development and technical professionals, chosen for the ordinary access their jobs already carried — not for their rank.

Protection

The Takeaways

  1. Never install a new 'reader' or app just to open a document — verify the sender and the job first.

  2. Move recruiting conversations off personal chat apps and onto the company's own hiring platform.

  3. Before responding further, open a new tab, go to the company's real website, and check its own careers page.

Companion Video

If you would like a visual explanation, continue with the accompanying CyberBlink video.

A recruiter message on a phone offering a senior role, next to a 'special reader' required to open the attached job description

The Job Offer That Was Too Good To Be True

A dramatized look at how a convincing job offer can turn into a real cyberattack, paired with the real UNC2970 fake-recruiter campaign this article investigates.

Now availableWatch on YouTube