Skip to content
June 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Google Exposes UNC6229 “Fake Career” Campaign Hacking Advertising Accounts with Fake Job Lures
  • Cybercriminals

Google Exposes UNC6229 “Fake Career” Campaign Hacking Advertising Accounts with Fake Job Lures

Do Son October 27, 2025 3 minutes read
0
UNC6229 Fake Career, Advertising Account Hack
Add as a preferred
source on Google

Google’s Threat Intelligence Group (GTIG) has exposed an ongoing social engineering campaign operated by a financially motivated threat cluster known as UNC6229, based in Vietnam. The group uses fake job postings on legitimate career platforms to trick digital marketing and advertising professionals into installing malware or revealing corporate credentials — ultimately compromising high-value advertising accounts for profit.

According to GTIG, “this campaign exploits the trust inherent in the job application process by posting fake career opportunities on popular employment platforms, as well as freelance marketplaces and their own job posting websites.”

The attackers specifically target remote digital advertising workers — often freelancers or contractors — who are more likely to manage multiple client accounts and use personal devices for business purposes.

GTIG explains that “if the target falls victim while logged into a work computer with a personal account, or while using a personal device with access to company ads accounts, threat actors can gain access to those company accounts.” Once inside, the attackers either hijack the company’s digital advertising accounts or sell access to other cybercriminals, monetizing the stolen credentials on underground markets.

The operation — internally dubbed “Fake Career” — begins with highly polished job listings posted on legitimate platforms such as LinkedIn and Indeed. These listings impersonate digital marketing agencies, complete with fabricated websites and social media profiles designed to appear credible.

“The effectiveness of this campaign hinges on a classic social engineering tactic where the victim initiates the first contact,” GTIG notes. “UNC6229 creates fake company profiles, often masquerading as digital media agencies, on legitimate job platforms. They post attractive, often remote, job openings that appeal to their target demographic.”

Once a candidate applies, attackers use the provided contact information to reach out — often via email or chat platforms — under the guise of recruiters. These initial messages are deliberately benign, meant to build trust before delivering the real payload.

In a move that makes detection significantly harder, UNC6229 has been observed abusing legitimate commercial SaaS platforms to manage communications and distribute payloads.

“GTIG has observed UNC6229 and other threat actors abusing a wide range of legitimate business and customer relationship management (CRM) platforms to send these initial emails and manage their campaigns,” the report states.

The group has even leveraged Salesforce and Google AppSheet for campaign coordination — exploiting their reputation to bypass email security filters. In response, GTIG said it “shared insights about these campaigns with CRMs UNC6229 has abused, including Salesforce, to better secure the ecosystem.”

Once trust is established, the attackers escalate to the payload delivery phase, sending either malware-laced attachments or phishing links disguised as part of the hiring process.

  • Malware Delivery: Victims receive a ZIP archive — often labeled as a “skills test” or “job application form.” Inside is a Remote Access Trojan (RAT) that, once executed, grants full control of the victim’s device.
  • Phishing Page: In other cases, candidates are directed to convincing interview scheduling portals that mimic the branding of companies like Microsoft or Google. These fake pages harvest login credentials and can even bypass multi-factor authentication (MFA) systems such as Okta.

GTIG assesses “with high confidence that this activity is conducted by a cluster of financially motivated individuals located in Vietnam.”

Related Posts:

  • Google: Zero-Day Exploits Shift from Browsers to Enterprise Security Tools in 2024

Related coverage

  • DeepSeek-R1 Chatbot Lure: BrowserVenom Malware Spreads via Google Ads, Hijacking Your Browser Traffic
  • Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets
  • Shadow Vector: Malicious SVGs Deliver AsyncRAT & RemcosRAT in Colombian Phishing Campaign!
  • Storm-2603: Chinese APT Deploys Warlock & LockBit with AK47C2 Framework
  • Inside BlueNoroff’s “Self-Reinforcing” Deepfake Meeting Trap

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Ad Account Takeover Fake Career Google Threat Intelligence phishing social engineering UNC6229 Vietnam

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.