Intel Name: Vietnamese actors using fake job posting campaigns to deliver malware and steal credentials
Date of Scan: October 29, 2025
Impact: High
Summary: A Vietnam-based threat cluster, tracked as UNC6229, is conducting fake job posting campaigns targeting digital marketing and advertising professionals. The group uses social engineering through legitimate employment platforms and fraudulent recruitment sites to deliver malware or steal credentials. Their objective is to gain access to corporate advertising and social media accounts for financial gain, including hijacking ad campaigns or selling compromised accounts. Related domains and malicious files have been blocked, and increased awareness of these tactics can help strengthen industry-wide defenses against this targeted, financially motivated operation.