Group-IB uncovered ResumeLooters, a threat actor group specializing in victimizing job hunters to steal their personally identifiable information (PII). Along with their in-depth threat analysis, they identified 15 indicators of compromise (IoCs), specifically seven domain names, three subdomains, and five IP addresses.
The WhoisXML API research team used the 15 IoCs as jump-off points for an expansion analysis in a bid to find more potential ResumeLooters attack vectors that led to the discovery of:
302 registrant-connected domains
69 email-connected domains
Six additional IP addresses, all of which turned out to be malicious
Three IP-connected domains
573 string-connected domains, two of which turned out to be malicious
A sample of the additional artifacts obtained from our analysis is available for download from our website.…