The Fake Recruiter: When a Dream Job Becomes a Cyberattack
A tailored job offer, sent by a recruiter who was never hiring at all. A documented 2024 espionage campaign shows how a real posting, a password-protected attachment, and one 'special reader' were enough to install a backdoor.
A job offer can arrive at exactly the right moment. The salary is strong, the company is real, and someone reached out to you specifically, based on your own background. That combination — flattering, specific, and well timed — is also the exact setup behind one of the more effective espionage campaigns documented in recent years.
The targets were not people scrolling job boards looking for work. They were working professionals already employed at real energy, aerospace, and defense-related companies, chosen because of the access their jobs already gave them, not because they were careless. And the 'recruiter' who contacted them was never hiring for anything at all.
Across documented UNC2970 campaigns, attackers have approached targets through recruiter personas, including professional networking platforms, email and WhatsApp — outside any system an employer's security team could see. The job description that followed looked legitimate because much of it was: the attackers reused real postings from real companies, editing only the details needed to fit the target.
The trap was the reader app packaged alongside the file. Because the attachment was encrypted, opening it required the tool the sender provided. Victims who ran it saw exactly what they expected — an ordinary job description on screen. In the background, the same program quietly loaded a backdoor and set up a scheduled task, so it kept running every time the computer restarted.
Nothing about this campaign relied on breaking into a company's network or exploiting a software flaw. The 'special reader' had no vulnerability in it at all — it was a working copy of a real program, quietly modified. The entire attack depended on one person trusting a message and running one file.
That is worth taking seriously even outside energy or defense work. UNC2970 targeted senior, well-connected employees specifically because of the systems and information their roles already touched, and researchers observed the group refining the same technique across more than one campaign. A convincing job offer is one of the few messages almost anyone will open without hesitation — which is exactly why it keeps getting reused.
None of this required a mistake anyone should feel embarrassed about — it required an unfamiliar verification habit. A few habits close the gap:
- Be suspicious if an unsolicited recruiter requires you to install a new reader, viewer, or application just to open a job description. Verify the recruiter and role independently before installing anything.
- Move any recruiting conversation off WhatsApp or personal email and onto the company's own hiring platform before sharing anything further.
- Treat a password-protected attachment from an unsolicited contact as a red flag on its own, regardless of how relevant the role sounds.
- Verify the opportunity directly on the company's own site before responding again, rather than through any link the message provides.
The verification step is short enough to remember under pressure: New Tab → Official Website → Careers → Verify. If the role isn't listed on the company's official careers site, verify it directly with the company through an independently obtained contact before proceeding.
General Guidance
CyberBlink Golden Rule: If an unsolicited job offer requires you to install unfamiliar software before you can even review the opportunity, stop and verify the recruiter and role independently first.
A common mistake
It is tempting to assume campaigns like this only threaten IT staff or executives. UNC2970's targets were business-development and technical professionals, chosen for the ordinary access their jobs already carried — not for their rank.
The Takeaways
Never install a new 'reader' or app just to open a document — verify the sender and the job first.
Move recruiting conversations off personal chat apps and onto the company's own hiring platform.
Before responding further, open a new tab, go to the company's real website, and check its own careers page.
Companion Video
If you would like a visual explanation, continue with the accompanying CyberBlink video.
The Job Offer That Was Too Good To Be True
A dramatized look at how a convincing job offer can turn into a real cyberattack, paired with the real UNC2970 fake-recruiter campaign this article investigates.