Threat reportMalwareTL-2026-1509
UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials
UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to (TL-2026-1509), also tracked as Fake Career campaign, is a high-severity malware campaign, first published 2026-07-19. It is attributed to UNC6229 (Vietnam) with high confidence, affects Cross-platform Remote digital advertising / marketing worker endpoints, maps to 22 MITRE ATT&CK techniques (T1027, T1056.001, T1071), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1UNC6229
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1509
- Threat ID
- TL-2026-1509
- Also known as
- Fake Career campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UNC6229
- Attribution confidence
- HIGH
- Nation-state nexus
- Vietnam
- Motivation
- FINANCIAL
- Target sectors
- advertising, marketing, digital media, social media management, remote contract workforce, recruiting hr
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to
Malware and tooling: Generic RAT (unnamed by GTIG)
How UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to works
Vietnam-based financially motivated threat cluster UNC6229 runs a persistent 'Fake Career' social engineering campaign, posting fake remote digital-advertising/marketing job listings on LinkedIn, freelance marketplaces, and attacker-owned sites (e.g. staffvirtual[.]website), then building rapport via legitimate CRM/collaboration platforms (Salesforce, Google Groups, Google AppSheet) before delivering password-protected ZIPs containing RATs or directing victims to Okta/Microsoft-branded MFA-bypass phishing kits to hijack corporate advertising and social-media accounts.
Google Threat Intelligence Group (GTIG) disclosed a cluster of financially motivated threat activity, tracked in part as UNC6229, operating from Vietnam and targeting remote/contract digital-advertising and marketing professionals worldwide. The actors exploit the inherent trust of the job-application process: fake postings are placed on legitimate platforms such as LinkedIn, on freelance marketplaces, and on threat-actor-owned recruiting websites (observed: staffvirtual[.]website). Unlike smash-and-grab phishing, UNC6229 uses a patient, multi-stage rapport-building approach — an initial benign, personalized outreach email establishes legitimacy before any malicious content is sent, and the actors abuse legitimate commercial CRM and workflow-automation platforms (Salesforce, Google Groups, Google AppSheet) to scale outreach while blending in with normal recruiting traffic.
Once a target engages, UNC6229 branches into two payload tracks. In the malware track, the victim receives a password-protected ZIP attachment framed as a mandatory 'skills test', application form, or preliminary task; opening and extracting it (using a supplied password to evade static/AV/attachment scanning) executes a remote access trojan (RAT) that grants the actor full device control, enabling session/cookie theft, keylogging, and direct hijacking of any online accounts (including advertising/social platforms) accessible from the compromised endpoint. In the phishing track, victims are redirected — often via shortened/obfuscated URLs — to convincing interview-scheduling or assessment portals cloned from Microsoft and Google branding; these pages harvest corporate credentials and are engineered to intercept and relay session tokens/OTPs to defeat MFA enforced through Okta and Microsoft identity platforms (adversary-in-the-middle style MFA bypass), enabling account takeover even where MFA is enabled.
Monetization is directly tied to the advertising-industry targeting focus: compromised advertising/social-media accounts are used to purchase fraudulent ads for resale, sold outright to other criminal actors, or used to harvest and resell curated lists of active job seekers to other threat actors — indicating UNC6229 operates within, or supplies, a broader Vietnamese cybercriminal ecosystem that exchanges tools, victim data, and techniques on private forums. GTIG assesses the campaign as active, ongoing, and likely to expand into additional industries and platforms as detection improves; Google has since blocklisted identified domains/files in Safe Browsing and coordinated with Salesforce and Google product teams to disable abused accounts.
MITRE ATT&CK techniques used in TL-2026-1509
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Credential Access
T1056.001 Keylogging; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Persistence
Discovery
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Impact
Collection
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587.001 Malware
Reconnaissance
T1589 Gather Victim Identity Information
reconnaissance
Affected products and versions in UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to
- Cross-platform — Remote digital advertising / marketing worker endpoints
Vulnerable versions: N/A - social engineering campaign, not a software vulnerability - Okta — Okta MFA / Identity Cloud
Vulnerable versions: Phishing-based MFA bypass via credential/session relay - Microsoft — Microsoft 365 / Entra ID MFA
Vulnerable versions: Phishing-based MFA bypass via credential/session relay
Remediation for UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to
Immediate actions
- Block/sinkhole staffvirtual[.]website and any newly discovered attacker-owned recruiting domains at DNS/proxy
- Alert on and block the published SHA256 malware hashes across EDR/AV
- Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) for Okta and Microsoft 365/Entra ID tenants to defeat token-relay MFA bypass
- Block execution of password-protected ZIP/archive attachments received from external senders at the email gateway, or detonate in a sandbox with supplied passwords extracted via OCR/body text
- Alert security/HR teams handling recruiting inboxes and remote-contractor applicants about the fake job posting lure pattern
Workarounds
- Require all incoming job-application-related archives to be opened only in an isolated/sandboxed environment, never on a device with access to corporate advertising or social media accounts
- Disable macro/script execution and restrict archive auto-extraction on endpoints used by remote contractors
Longer-term hardening
- Deploy EDR with behavioral detection for RAT installation, unusual archive-extraction-to-execution chains, and anomalous outbound C2 beaconing
- Implement conditional access policies restricting sign-ins to managed/compliant devices for advertising and social-media platform administrators
- Establish a vetted, out-of-band process for issuing 'skills test' or onboarding files to remote/contract job candidates that avoids ad hoc email attachments
- Monitor Salesforce, Google Groups, and Google AppSheet tenant abuse patterns (bulk outbound messaging from new/low-reputation accounts) and report to platform trust & safety teams
- Conduct security awareness training for advertising/marketing/HR staff specifically on recruitment-themed social engineering and MFA-bypass phishing
Timeline of UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to
- GTIG assesses UNC6229 'Fake Career' social engineering activity as an ongoing, persistent campaign predating public disclosure, targeting remote digital advertising and marketing professionals.
- Multiple security news outlets (SecurityOnline, CyberPress, GBHackers, CyberSecurityNews, News4Hackers) republish and analyze the GTIG findings.
- Google coordinates with Salesforce and internal Google Groups/AppSheet teams to disable threat-actor-controlled accounts abusing those platforms for outreach.
- Google adds identified UNC6229 websites, domains, and malicious files to Safe Browsing blocklists.
- GTIG publishes IOCs including the staffvirtual[.]website domain and five SHA256 malware hashes associated with the campaign.
- Google Threat Intelligence Group publishes 'Help Wanted' report publicly disclosing UNC6229, its fake job posting lures, RAT/phishing-kit payloads, and CRM-platform abuse.
- FPT-IS publishes independent analysis of the recruitment-trap technique used by the Vietnamese threat cluster.
- TL-Intel-Harness ingests the GTIG UNC6229 disclosure into the pipeline for research/detection engineering under TL-2026-1509.
Sources cited for UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to
- Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials
- Google Exposes UNC6229 "Fake Career" Campaign Hacking Advertising Accounts with Fake Job Lures
- Hackers Exploit Fake Job Listings in Credential Theft Scheme, Google Reports
- Google Warns of Cybercriminals Using Fake Job Postings to Spread Malware and Steal Credentials
- UNC6229 "Fake Career" Campaign Hacking Advertising A/cs with Fake Jobs Exposed by Google
- Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials (Threat Radar)
- Fake Job Offers: The Recruitment Trap by Vietnamese Hackers
- Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials (Malware News aggregation)
- Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials
Detection coverage for TL-2026-1509
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1509 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.