Skip to content
BlackSanta Campaign Targets HR with Malware-laden Job Applications

BlackSanta Campaign Targets HR with Malware-laden Job Applications

First seen 10 Mar 2026, 13:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A Russian-speaking cybercriminal group, dubbed BlackSanta, is targeting corporate HR teams by sending fake job applications that install malware capable of disabling endpoint detection and response (EDR) tools. This campaign exploits the hiring process, using seemingly legitimate resumes hosted on familiar cloud storage services to infiltrate organizations and steal sensitive data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-03-10
BlackSanta campaign reported targeting HR workflows
2026-03-10
Malware identified that disables EDR tools
2026-03-10
Fake job applications used as attack vector

More articles in this cluster (7)

Following this threat?

Track BlackSanta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed