WordPress ClickFix Plugin Critical Flaw Lets Attackers Deploy Amatera Stealer
Key Takeaways A sophisticated phishing campaign is targeting researchers with fake resumes. The attacks deploy SNOWLIGHT and the VShell remote-access trojan. The malicious payload is delivered via a...
Key Takeaways
- A sophisticated phishing campaign is targeting researchers with fake resumes.
- The attacks deploy SNOWLIGHT and the VShell remote-access trojan.
- The malicious payload is delivered via a multi-stage, memory-based infection chain, making detection more challenging.
- The lures are tailored for technical academics, often claiming to be from a Beijing Institute of Technology graduate.
- Academic staff and IT teams are urged to exercise extreme caution with unsolicited applications and implement robust security measures.
Cybersecurity researchers are sounding the alarm over a cunning new campaign that leverages fake student resumes to infiltrate Windows computers belonging to academic staff. This targeted attack aims to install a remote-access tool, allowing adversaries to gain a covert foothold on research workstations.
Table Of Content
The deceptive campaign involves a malicious archive, disguised as a graduate school application, that surreptitiously executes a Windows executable. While the victim observes a legitimate Word document opening, the infection process unfolds silently in the background, establishing persistent remote access.
The Deceptive Lure
The malicious lures are crafted to appear as applications from a recent graduate of the Beijing Institute of Technology. These fabricated resumes often highlight expertise in electrical engineering, energy systems, and applied artificial intelligence. This specific focus strongly suggests that the primary targets are university professors and laboratory personnel, rather than general corporate recruiters. The attackers exploit the inherent trust within academic correspondence to establish an intrusion vector.
As noted by Himanshu Anand in a report shared with Cyber Security News (CSN), the attack chain delivers the SNOWLIGHT loader and the VShell remote-access trojan through a sophisticated multi-stage, memory-resident process. While evidence points to a clear objective of compromising research workstations, the identity, nationality, or ultimate goals of the operators remain unconfirmed.
This incident underscores the critical need for academic institutions to adopt the same rigorous security protocols typically employed by corporate hiring departments. The believability of these fake applications capitalizes on the expectation that researchers will frequently review unfamiliar files. The inclusion of a genuine-looking decoy document further lulls victims into a false sense of security, giving them little reason to suspect a malicious payload.
Infection Chain and Evasion
The initial malicious ZIP archive is given a Chinese-language filename, purporting to be from a network engineering graduate named Zhang Yuguang. Inside this archive lies an executable file, named almost identically to a document, which exploits Windows’ default behavior of hiding known file extensions. This makes the executable appear as a regular document to an unsuspecting user.
Upon execution, the loader retrieves and displays a legitimate DOCX resume, creating the illusion of a harmless application review. Concurrently, the malware performs environmental checks, specifically avoiding systems with fewer than four CPU cores and employing unusual timing tests, all designed to evade detection by analysis environments.
The content of the decoy resume, discussing topics such as AI-based power-grid fault diagnosis, renewable energy control, and joining a supervisor’s research group, indicates that the attackers meticulously tailored the lure for technical academics. Similar tactics have been observed in attacks involving academic event materials, where trusted research contexts were exploited as cover. While the university name lends credibility to the application, it does not imply that the institution was involved in or aware of the malware distribution.
Anand’s analysis suggests that the most probable target context is a mainland Chinese academic recipient, although the specific attribution of the operator remains elusive.
Instead of writing a traditional payload to disk, the initial program downloads encrypted shellcode and executes it directly in memory. This fileless approach significantly hinders detection by conventional disk-based antivirus solutions, as it leaves minimal forensic traces on the file system, all while the decoy document remains open and visible to the victim.
SNOWLIGHT and VShell: Enabling Remote Access
The Windows SNOWLIGHT shellcode initiates contact with its command and control (C2) server. After a brief system check-in, it receives a substantial 4.65 MB payload. This payload is then decoded, and execution is transferred to VShell, which subsequently registers with the same C2 server using encrypted communications.
This sequence successfully establishes a remote-access foothold for the attackers. While the analysis confirmed VShell’s registration and health checks, it did not capture specific operator activities such as command execution, file transfers, or lateral movement within the network. It is crucial to differentiate between confirmed behavior and the full range of capabilities that VShell can afford. VShell is known to provide an interactive command shell, file transfer functionalities, screen capture, network discovery, and tunneling capabilities. Its broader use by various threat actors has been documented in analyses of VShell threat actor adoption, but the framework itself does not definitively identify a particular threat group.
This distinction is particularly relevant here, as both SNOWLIGHT and VShell have been observed in activities attributed to multiple clusters, suggesting their increasing availability and adoption across different threat groups. The report therefore characterizes this as an unattributed actor utilizing an academic lure with a mainland China orientation, rather than a definitively state-sponsored operation.
What You Should Do
- Verify Unsolicited Applications: Academic staff, departments, and IT teams should always verify unsolicited applications through an independent contact channel before opening any attached files.
- Enable Visible File Extensions: Configure Windows to show known file extensions to help identify disguised executables (e.g.,
.zipcontaining.exemasquerading as.docx). - Block Executable Content: Implement policies to block executable content within unexpected archive files.
- Monitor for Suspicious Activity: Investigate any resume-themed programs that initiate command shells, launch Microsoft Word in unusual ways, or establish abnormal outbound network connections.
- Educate Users: Conduct regular cybersecurity awareness training for academic staff on phishing tactics, especially those involving social engineering lures like fake resumes.
- Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to detect and respond to fileless malware and in-memory execution.
- Network Monitoring: Security teams should actively hunt for the listed Indicators of Compromise (IoCs), including suspicious network destinations, resume-themed executables, and temporary markers associated with this attack chain. Review related process and network telemetry for anomalies.
- Review IoCs: Integrate the following IoCs into your security monitoring and detection systems.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Archive filename | Beijing Institute of Technology_network engineering major_fresh graduate_Zhang Yuguang_personal resume (2)(1).zip |
Malicious archive used as the initial delivery container |
| SHA-256 | c25d4412f7f93e7de5b2aaf41747175d94cffd983ca20efbd0efcdd718b58c4d |
Original malicious archive |
| SHA-256 | 81c51138d5527ca7dcc258171eb36659c479f66c86a8947b6340d040b3860a30 |
Go loader |
| MD5 | a7cc7e3cdd2f0f9210044911a483fa5d |
Go loader |
| SHA-256 | f6d4da5afc89bf9e536a9002c4d256c696df2389d77279f4c5daf6979557e74e |
Encrypted HTTP response |
| SHA-256 | 0524619d2471d77aba4b7993f5ffbaa4b8be6d2c0d91e63a02943851dc4b6404 |
SNOWLIGHT shellcode |
| SHA-256 | ed2eaa6ef3eda95383b6efc35b88acbca742ad7bd118931f74727a3139ff7e97 |
XOR-encoded VShell payload stream |
| SHA-256 | c666ac4f1a1b8df7ccfe8b19705279acd8b7eb7a4d0b3802bb3465064883ab25 |
Decoded VShell payload |
| SHA-256 | de3f56d0d5b71f2a1a1905f0b01b84fbab237e9d4c5179a05b127d806823f83c |
DOCX resume decoy |
| IP address | 38.207.178.192 |
Campaign command-and-control and staging server |
| URL | http://38.207.178.192:50813/EasyConnectUpdata_Log.txt |
Encrypted shellcode staging location |
| URL | http://38.207.178.192:50813/MySQL_LOG.txt |
Word document decoy staging location |
| Network service | 38.207.178.192:50813 |
HTTP staging service |
| Network service | 38.207.178.192:50812 |
SNOWLIGHT check-in and VShell transfer service |
| AES key | YtWzxwZimsZoeMen |
Embedded loader configuration decryption key |
| XOR key | 0x99 |
Key used to decode the received VShell payload |
| Filename | TEMPde.log |
SNOWLIGHT kill-switch or operator exclusion marker |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.