A hacking group known as FIN6 is targeting recruiters with malware hidden in CV links. Posing as candidates on LinkedIn and Indeed, the attackers send CVs that contain disguised malware. Victims receive a zip file containing a shortcut which installs the malware capable of stealing credentials and remote access, and using legitimate Windows utilities to evade detection.

This invisible malware hijacks checkout pages using trusted Google URLs, and you’ll never see it coming
Malicious attackers have found a new way of bypassing antivirus programs by infiltrating browsers with malware that is activated during the checkout process on ecommerce