Russian-Speaking Hackers Deploy BlackSanta Malware Against HR Departments

Russian-Speaking Hackers Deploy BlackSanta Malware Against HR Departments

First seen 11 Mar 2026, 12:43 UTC Feeds2.FeedburnerHackreadCybersecurity-ReviewSecurityboulevard 65.3

Article Content

Browse articles
ThreatCluster

A sophisticated cyber attack campaign has been targeting HR departments and recruiters globally, utilizing a new malware named 'BlackSanta'. This campaign, attributed to Russian-speaking threat actors, has been active for over a year, employing tactics that allow it to evade detection by antivirus and endpoint protection systems. The malware disguises itself as job applications, effectively infiltrating recruitment workflows. Aryaka researchers have reported that the attackers use a specialized module to disable security software, complicating detection efforts. Currently, the extent of the campaign remains unclear due to a lack of telemetry data. Organizations in various sectors are likely affected, but specific numbers and impacted systems have not been disclosed. The situation is ongoing, with researchers emphasizing the need for heightened vigilance among HR and recruitment teams.

Key Points: • BlackSanta malware targets HR departments by masquerading as job applications. • Attackers disable antivirus and endpoint protection to evade detection. • The campaign has been active for over a year, with unclear scope and impact.

Timeline

2025-01-01
BlackSanta malware campaign reportedly began.
2026-03-10
Aryaka researchers publish findings on the attack.
2026-03-11
Multiple cybersecurity outlets report on BlackSanta malware.