Threat reportMalwareTL-2026-1509

UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials

highACTIVE

UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to (TL-2026-1509), also tracked as Fake Career campaign, is a high-severity malware campaign, first published 2026-07-19. It is attributed to UNC6229 (Vietnam) with high confidence, affects Cross-platform Remote digital advertising / marketing worker endpoints, maps to 22 MITRE ATT&CK techniques (T1027, T1056.001, T1071), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
1UNC6229
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-1509

Threat ID
TL-2026-1509
Also known as
Fake Career campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC6229
Attribution confidence
HIGH
Nation-state nexus
Vietnam
Motivation
FINANCIAL
Target sectors
advertising, marketing, digital media, social media management, remote contract workforce, recruiting hr
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
15

Malware and tooling in UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to

Malware and tooling: Generic RAT (unnamed by GTIG)

How UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to works

Vietnam-based financially motivated threat cluster UNC6229 runs a persistent 'Fake Career' social engineering campaign, posting fake remote digital-advertising/marketing job listings on LinkedIn, freelance marketplaces, and attacker-owned sites (e.g. staffvirtual[.]website), then building rapport via legitimate CRM/collaboration platforms (Salesforce, Google Groups, Google AppSheet) before delivering password-protected ZIPs containing RATs or directing victims to Okta/Microsoft-branded MFA-bypass phishing kits to hijack corporate advertising and social-media accounts.

Google Threat Intelligence Group (GTIG) disclosed a cluster of financially motivated threat activity, tracked in part as UNC6229, operating from Vietnam and targeting remote/contract digital-advertising and marketing professionals worldwide. The actors exploit the inherent trust of the job-application process: fake postings are placed on legitimate platforms such as LinkedIn, on freelance marketplaces, and on threat-actor-owned recruiting websites (observed: staffvirtual[.]website). Unlike smash-and-grab phishing, UNC6229 uses a patient, multi-stage rapport-building approach — an initial benign, personalized outreach email establishes legitimacy before any malicious content is sent, and the actors abuse legitimate commercial CRM and workflow-automation platforms (Salesforce, Google Groups, Google AppSheet) to scale outreach while blending in with normal recruiting traffic.

Once a target engages, UNC6229 branches into two payload tracks. In the malware track, the victim receives a password-protected ZIP attachment framed as a mandatory 'skills test', application form, or preliminary task; opening and extracting it (using a supplied password to evade static/AV/attachment scanning) executes a remote access trojan (RAT) that grants the actor full device control, enabling session/cookie theft, keylogging, and direct hijacking of any online accounts (including advertising/social platforms) accessible from the compromised endpoint. In the phishing track, victims are redirected — often via shortened/obfuscated URLs — to convincing interview-scheduling or assessment portals cloned from Microsoft and Google branding; these pages harvest corporate credentials and are engineered to intercept and relay session tokens/OTPs to defeat MFA enforced through Okta and Microsoft identity platforms (adversary-in-the-middle style MFA bypass), enabling account takeover even where MFA is enabled.

Monetization is directly tied to the advertising-industry targeting focus: compromised advertising/social-media accounts are used to purchase fraudulent ads for resale, sold outright to other criminal actors, or used to harvest and resell curated lists of active job seekers to other threat actors — indicating UNC6229 operates within, or supplies, a broader Vietnamese cybercriminal ecosystem that exchanges tools, victim data, and techniques on private forums. GTIG assesses the campaign as active, ongoing, and likely to expand into additional industries and platforms as detection improves; Google has since blocklisted identified domains/files in Safe Browsing and coordinated with Salesforce and Google product teams to disable abused accounts.

MITRE ATT&CK techniques used in TL-2026-1509

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Credential Access

T1056.001 Keylogging; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Persistence

T1078 Valid Accounts

Discovery

T1087 Account Discovery

Execution

T1204.001 Malicious Link; T1204.002 Malicious File

Impact

T1531 Account Access Removal

Collection

T1560 Archive Collected Data

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587.001 Malware

Reconnaissance

T1589 Gather Victim Identity Information

reconnaissance

T1598.003 Spearphishing Link

Affected products and versions in UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to

  • Cross-platform — Remote digital advertising / marketing worker endpoints
    Vulnerable versions: N/A - social engineering campaign, not a software vulnerability
  • Okta — Okta MFA / Identity Cloud
    Vulnerable versions: Phishing-based MFA bypass via credential/session relay
  • Microsoft — Microsoft 365 / Entra ID MFA
    Vulnerable versions: Phishing-based MFA bypass via credential/session relay

Remediation for UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to

Immediate actions

  • Block/sinkhole staffvirtual[.]website and any newly discovered attacker-owned recruiting domains at DNS/proxy
  • Alert on and block the published SHA256 malware hashes across EDR/AV
  • Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) for Okta and Microsoft 365/Entra ID tenants to defeat token-relay MFA bypass
  • Block execution of password-protected ZIP/archive attachments received from external senders at the email gateway, or detonate in a sandbox with supplied passwords extracted via OCR/body text
  • Alert security/HR teams handling recruiting inboxes and remote-contractor applicants about the fake job posting lure pattern

Workarounds

  • Require all incoming job-application-related archives to be opened only in an isolated/sandboxed environment, never on a device with access to corporate advertising or social media accounts
  • Disable macro/script execution and restrict archive auto-extraction on endpoints used by remote contractors

Longer-term hardening

  • Deploy EDR with behavioral detection for RAT installation, unusual archive-extraction-to-execution chains, and anomalous outbound C2 beaconing
  • Implement conditional access policies restricting sign-ins to managed/compliant devices for advertising and social-media platform administrators
  • Establish a vetted, out-of-band process for issuing 'skills test' or onboarding files to remote/contract job candidates that avoids ad hoc email attachments
  • Monitor Salesforce, Google Groups, and Google AppSheet tenant abuse patterns (bulk outbound messaging from new/low-reputation accounts) and report to platform trust & safety teams
  • Conduct security awareness training for advertising/marketing/HR staff specifically on recruitment-themed social engineering and MFA-bypass phishing

Timeline of UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to

  • GTIG assesses UNC6229 'Fake Career' social engineering activity as an ongoing, persistent campaign predating public disclosure, targeting remote digital advertising and marketing professionals.
  • Multiple security news outlets (SecurityOnline, CyberPress, GBHackers, CyberSecurityNews, News4Hackers) republish and analyze the GTIG findings.
  • Google coordinates with Salesforce and internal Google Groups/AppSheet teams to disable threat-actor-controlled accounts abusing those platforms for outreach.
  • Google adds identified UNC6229 websites, domains, and malicious files to Safe Browsing blocklists.
  • GTIG publishes IOCs including the staffvirtual[.]website domain and five SHA256 malware hashes associated with the campaign.
  • Google Threat Intelligence Group publishes 'Help Wanted' report publicly disclosing UNC6229, its fake job posting lures, RAT/phishing-kit payloads, and CRM-platform abuse.
  • FPT-IS publishes independent analysis of the recruitment-trap technique used by the Vietnamese threat cluster.
  • TL-Intel-Harness ingests the GTIG UNC6229 disclosure into the pipeline for research/detection engineering under TL-2026-1509.

Sources cited for UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to

Detection coverage for TL-2026-1509

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1509 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats