Fake Job Sites Targeting Tech Professionals, Says Unit 42

Recruitment portals have become a vehicle for cyber attacks.
Iranian hackers are using fake job postings to deploy malware against technology and engineering professionals across the US, Israel and UAE.
According to Palo Alto Networks' Unit 42, the threat group known as Screening Serpens deployed six new remote access Trojan variants between February and April 2026.
The group operates under several aliases including Smoke Sandstorm, Iranian Dream Job and UNC1549.
The attacks targeted organisations through personalised phishing that mimicked legitimate hiring processes. Additional entities across the Middle East may also have been affected, according to Unit 42 researchers.
Recruitment lures target professionals
Screening Serpens relied on personalised phishing attacks disguised as recruitment opportunities.
Fake hiring portals, spoofed employment websites and tailored job descriptions worked together to trick technology and engineering professionals into downloading malicious files.
In one campaign, attackers impersonated a global airline and distributed fake job applications containing malware-laden ZIP files.
Another relied on fraudulent recruitment links designed to resemble trusted employment platforms.
The level of personalisation suggests attackers conducted extensive reconnaissance on intended victims before launching attacks.
The campaigns used Azure-hosted command and control infrastructure, helping malicious traffic blend in with legitimate cloud activity.
Security researchers noted that the threat actors demonstrated a continuous cycle of malware development and deployment throughout the conflict period, adapting techniques and rotating infrastructure to improve resilience and reduce detection rates.
The attacks exploited the trust professionals place in recruitment communications.
Candidates actively seeking opportunities are more likely to engage with unsolicited approaches that appear to offer career advancement, particularly when messages reference specific skills or experience listed on professional networking sites.
Malware disables security mechanisms
Unit 42 identified the malware families as MiniUpdate, a newly discovered family, and MiniJunk V2, an evolved iteration of MiniJunk.
These payloads steal data and allow attackers to remotely execute commands on infected devices.
The attacks used AppDomainManager hijacking to manipulate .NET applications.
By disabling security mechanisms during start-up, the deployed malware could execute freely.
"As APT groups like Screening Serpens continue to evolve and leverage advanced frontier AI technologies, legacy endpoint security solutions are no longer enough," says Elad Koren, VP of Product Management at Palo Alto Networks.
"Modern organisations now require defensive postures that transition toward multi-layered, behavioural-based strategies that look beyond simple file signatures."
Elad adds that defenders can intercept attack chains by focusing on identifying anomalous behaviours at the point of installation, such as AppDomain hijacking or the disabling of system telemetry.
"Monitoring application logic and behaviour is now foundational to proactive threat prevention," he says.
Behavioural detection methods needed
The report from Palo Alto Networks suggests conventional antivirus and signature-based detection systems are struggling to keep pace with state-sponsored cyber threats.
Organisations are being urged to strengthen behavioural monitoring capabilities that can identify suspicious activity patterns in real time.
Unit 42 researchers recommended increased monitoring for DLL sideloading and AppDomainManager hijacking techniques, both of which played a central role in the campaigns.
By exploiting trusted applications and legitimate configuration files, attackers were able to bypass many traditional security controls.
Screening Serpens activity showed no signs of slowing during March and April 2026.
Researchers believe further attacks targeting technology, defence and telecommunications sectors are likely in the near future.
The findings suggest recruitment processes require additional security measures.
HR teams handling applications for technology and engineering roles may need to work with security teams to verify the authenticity of candidate interactions and file submissions.


