# UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials

> Vietnam-based financially motivated threat cluster UNC6229 runs a persistent 'Fake Career' social engineering campaign, posting fake remote digital-advertising/marketing job listings on LinkedIn, freelance marketplaces, and attacker-owned sites (e.g. staffvirtual[.]website), then building rapport via legitimate CRM/collaboration platforms (Salesforce, Google Groups, Google AppSheet) before delivering password-protected ZIPs containing RATs or directing victims to Okta/Microsoft-branded MFA-bypass phishing kits to hijack corporate advertising and social-media accounts.

- **Published:** 2026-07-19T00:00:00Z
- **Last reviewed:** 2026-07-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1509
- **ID:** TL-2026-1509
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC6229 (Vietnam)
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Google Threat Intelligence Group (GTIG) disclosed a cluster of financially motivated threat activity, tracked in part as UNC6229, operating from Vietnam and targeting remote/contract digital-advertising and marketing professionals worldwide. The actors exploit the inherent trust of the job-application process: fake postings are placed on legitimate platforms such as LinkedIn, on freelance marketplaces, and on threat-actor-owned recruiting websites (observed: staffvirtual[.]website). Unlike smash-and-grab phishing, UNC6229 uses a patient, multi-stage rapport-building approach — an initial benign, personalized outreach email establishes legitimacy before any malicious content is sent, and the actors abuse legitimate commercial CRM and workflow-automation platforms (Salesforce, Google Groups, Google AppSheet) to scale outreach while blending in with normal recruiting traffic.

Once a target engages, UNC6229 branches into two payload tracks. In the malware track, the victim receives a password-protected ZIP attachment framed as a mandatory 'skills test', application form, or preliminary task; opening and extracting it (using a supplied password to evade static/AV/attachment scanning) executes a remote access trojan (RAT) that grants the actor full device control, enabling session/cookie theft, keylogging, and direct hijacking of any online accounts (including advertising/social platforms) accessible from the compromised endpoint. In the phishing track, victims are redirected — often via shortened/obfuscated URLs — to convincing interview-scheduling or assessment portals cloned from Microsoft and Google branding; these pages harvest corporate credentials and are engineered to intercept and relay session tokens/OTPs to defeat MFA enforced through Okta and Microsoft identity platforms (adversary-in-the-middle style MFA bypass), enabling account takeover even where MFA is enabled.

Monetization is directly tied to the advertising-industry targeting focus: compromised advertising/social-media accounts are used to purchase fraudulent ads for resale, sold outright to other criminal actors, or used to harvest and resell curated lists of active job seekers to other threat actors — indicating UNC6229 operates within, or supplies, a broader Vietnamese cybercriminal ecosystem that exchanges tools, victim data, and techniques on private forums. GTIG assesses the campaign as active, ongoing, and likely to expand into additional industries and platforms as detection improves; Google has since blocklisted identified domains/files in Safe Browsing and coordinated with Salesforce and Google product teams to disable abused accounts.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1585 Establish Accounts
- T1583.001 Domains
- T1584 Compromise Infrastructure
- T1587.001 Malware
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1204.001 Malicious Link
- T1078 Valid Accounts
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1111 Multi-Factor Authentication Interception
- T1598.003 Spearphishing Link
- T1539 Steal Web Session Cookie
- T1056.001 Keylogging
- T1621 Multi-Factor Authentication Request Generation
- T1087 Account Discovery
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1219 Remote Access Tools
- T1531 Account Access Removal

## Sources

- [Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials](https://cloud.google.com/blog/topics/threat-intelligence/vietnamese-actors-fake-job-posting-campaigns/)
- [Google Exposes UNC6229 "Fake Career" Campaign Hacking Advertising Accounts with Fake Job Lures](https://securityonline.info/google-exposes-unc6229-fake-career-campaign-hacking-advertising-accounts-with-fake-job-lures/)
- [Hackers Exploit Fake Job Listings in Credential Theft Scheme, Google Reports](https://cyberpress.org/fake-job-listings/)
- [Google Warns of Cybercriminals Using Fake Job Postings to Spread Malware and Steal Credentials](https://gbhackers.com/fake-job-postings/)
- [UNC6229 "Fake Career" Campaign Hacking Advertising A/cs with Fake Jobs Exposed by Google](https://www.news4hackers.com/unc6229-fake-career-campaign-hacking-advertising-a-cs-with-fake-jobs-exposed-by-google/)
- [Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials (Threat Radar)](https://radar.offseq.com/threat/help-wanted-vietnamese-actors-using-fake-job-posti-b7d16ca8)
- [Fake Job Offers: The Recruitment Trap by Vietnamese Hackers](https://fpt-is.com/en/insights/when-job-opportunities-become-a-fake/)
- [Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials (Malware News aggregation)](https://malware.news/t/help-wanted-vietnamese-actors-using-fake-job-posting-campaigns-to-deliver-malware-and-steal-credentials/100496)
- [Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials](https://cybersecuritynews.com/google-warns-of-threat-actors-using-fake-job-posting/amp/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1509
