North Korea-linked hackers use fake job offers to target energy industry
A North Korea-affiliated cyber-espionage group, UNC2970, is tricking people in the energy and aerospace industries with fake job offers to gain access to sensitive information. The hackers send phishing emails, pretending to be recruiters offering high-level jobs. When victims open the job descriptions, they unknowingly download malware called MISTPEN, a tool that gives hackers control over their computers.
This cyber group has been active since 2013 and is believed to be working for North Korea’s intelligence agency. They have targeted countries like the U.S., U.K., Germany, Australia, and others, focusing on senior-level employees to steal important data.
The group uses a known tactic where they send a malicious file disguised as a job posting. When victims try to open it, they are prompted to use an old version of a PDF reader, which installs the malware. This allows the hackers to access the system and download more harmful programs without detection.