The Next Driver Applicant in Your Inbox Might Be a Hacker
Security researchers have tracked attackers posing as job candidates and sending malware disguised as resumes. A driver recruiting inbox has exactly the exposure this tactic needs.
Is this a real, documented attack, or just a theoretical risk?
Here's what's actually happening: security researchers have documented multiple active campaigns where attackers pose as job applicants and send malware disguised as resumes, cover letters, or portfolio links directly to the people responsible for reviewing applications. This is not a hypothetical extension of phishing awareness training. It is a named, tracked pattern with real victims, and the entire mechanism depends on exactly the behavior every recruiting inbox is built around: opening attachments from strangers because that is the job.
How does the fake-applicant attack actually work?
Security firm DomainTools identified a campaign by the financially motivated group FIN6, also tracked as Skeleton Spider, in which attackers built realistic applicant personas on platforms like LinkedIn and Indeed. They engaged recruiters in professional back-and-forth conversation to build trust, then sent non-clickable resume URLs that the recruiter had to type into a browser manually. This technique was designed to slip past email security tools that scan embedded links. The landing pages were hosted on legitimate cloud infrastructure and delivered malware to recruiters who followed through.
A separate campaign tracked as TA4557 or Venom Spider uses a similar approach with malware called More_eggs. Once installed, it can harvest credentials for email, banking, and administrator accounts. Trend Micro researchers documented a real case where a recruitment officer downloaded a file called John Cboins.zip, believing it was a candidate's resume, and triggered a More_eggs backdoor infection. Aryaka researchers later documented malicious resumes sent to HR departments as ISO attachments that ran hidden PowerShell commands after being opened.
This is not a fringe problem. Amazon publicly disclosed that it blocked more than 1,800 job applications suspected of coming from North Korean state-linked actors over a 17-month period. That gives a sense of the scale even before financially motivated criminal groups running similar campaigns are counted.
Why is a driver recruiting inbox a particularly good target?
Driver recruiting depends on being open to strangers, at volume, on a fast timeline. A recruiter handling CDL applications is expected to open resumes, license scans, and application documents from people they have never met. They often do it under pressure to fill seats because every empty truck represents lost revenue. That is exactly the working environment these campaigns exploit: reviewing unsolicited documents from unknown senders is not unusual behavior here. It is the job.
Security researchers describe this professional obligation as the entry point. Once an attacker gets past recruiting, their activity can appear more legitimate than an outside attack because it begins inside a normal hiring conversation.
What does a malicious application actually look like?
- β A professionally written message with no obvious red flags. Modern fake applications often use polished, error-free language.
- β A resume URL that must be copied and pasted manually. This can avoid automated checks that inspect clickable links.
- β A ZIP or ISO file instead of a normal PDF or Word document. Archive formats can conceal a shortcut or executable.
- β A real conversation before the file arrives. Some attackers spend several messages building trust before sending anything malicious.
- β A file hosted on a familiar cloud platform. Legitimate infrastructure can make a dangerous download look routine.
What can carriers actually do about it?
Protecting the recruiting inbox does not require turning away real applicants or slowing hiring to a crawl:
- β Open application attachments in a sandboxed or isolated environment where possible, not on the recruiter's primary workstation.
- β Be cautious of resume links that require someone to type or paste a URL manually. That is a documented evasion technique.
- β Treat ZIP and ISO attachments from unsolicited applicants as high risk. Legitimate driver applications rarely need those formats.
- β Keep endpoint detection active on every computer that handles recruiting email and applicant documents.
- β Train recruiting staff on fake-applicant campaigns specifically, not only on generic phishing messages.
01Is this a real, documented attack, or just a theoretical risk?
+
02Has a trucking company specifically been targeted by this?
+
03Wouldn't our email security software catch a malicious resume?
+
04Does this mean we should stop accepting applications by email?
+
05How is this different from phishing involving rate confirmations and broker impersonation?
+
Protect recruiting before a fake applicant becomes a real incident.
Trucky and We Secure review the inboxes, devices, credentials, and workflows attackers can use to enter your operation.
Train your recruiting team to spot threats and keep qualified drivers moving.
Trucky builds practical recruiting processes for carriers, from applicant screening to recruiter training and orientation handoff.
DomainTools research on FIN6 via GovInfoSecurity Β· Arctic Wolf Labs research on TA4557 via SHRM Β· Trend Micro research on More_eggs via The Hacker News Β· Aryaka research on malicious ISO resume attachments via CSO Online Β· Amazon disclosure on suspected fraudulent job applications.
Book a 30-minute strategy call.
Walk away with a plan - even if we never work together.
Book a call β
