Fake résumé emails attempt to spread Ordinypt Wiper

Attention German HR departments: You may want to cross off a certain "Eva Richter" from your list of employment candidates. Especially because her so-called résumé actually infects recipients with the destructive Ordinypt Wiper malware, according to a new report.
The fake résumé phishing campaign began on Sept. 11 and is specifically aimed at German-speaking employers, Bleeping Computer reported this past weekend. The campaign sends an email that appears to be a job application, replete with photo and résumé of one Eva Richter. But in reality, the photo is a random stock photo and the résumé is a PDF file that delivers Ordinypt.
Historically, Ordinypt targets Germans acts very much like a typical ransomware program. It maliciously encrypts victims’ files and demands payment via a Tor site to restore the files. However, in this instance, even if the victim pays up, the files remain useless because they are overwritten with random characters.
Ordinypt also deletes shadow volume copies and disables the Windows 10 recovery environment in an attempt to further frustrate the victim. However, in some instances of infection, the shadow volume copies survive, BleepingComputer notes.
"Dear Sirs and Madames, I hereby apply for the position offered by you at the Employment Agency," the fake email reads. "The field of activity you describe corresponds, especially to my career prospects. My application documents are attached. I would be very happy about an invitation to a personal job interview. Yours sincerely, Eva Richter."
So, if you’re looking for a job in Germany and your name coincidentally just happens to be Eva Richter, well, perhaps consider a name change until this latest phishing campaign blows over.
source scmagazineuk
Industry: Cyber Security

Latest Jobs
-
- Outside IR 35 CONTRACT SC CLEARED Cyber Security Operations Analyst SPLUNK ES- UK REMOTE- £500 a day.
- N/A
- 500
-
6 month contract Outside IR35 Operational Cyber Security Analyst. Hands on Splunk Security Enterprise and Security clearance is required As is someone that holds SC clearance. SOC and Vulnerability management experience. Vulnerability Analysis / Management - Tenable
-
- SailPoint Consultant
- Sweden
- Upto €80,000
-
SailPoint Consultant is need for this rapidly expanding global business, The business is currently in the middle of a SailPoint Deployment, they require an experienced Consultant who is able to help them on this Journey You will be responsible for helping to configure and deploy SailPoint as well as on board applications onto the platform You will also work with the business to understand workflow and process to help align the way the business works to ensure that the business gets the most from the deployment We are looking for an experienced SailPoint consultant who has experience with both Deployment and BAU work and is interested in joining a business which is at the start of an interesting IAM Journey
-
- SOC Manager Security Operations. SIEM, Threat / Vulnerability, IR, SOC Service- Exclusive
- United Kingdom
- 90,000+
-
SOC Manager- SIEM, Threat / Vulnerability, Incident response. Exclusive Project. Management and on growth growth of Security Operations Centre capability. Managing and maturing the team, technical services line and fronting client engagements where needed. An in-depth technical background is essential, experience across SOC SIEM/ Threat Hunting (IR) tools, processes, techniques, operational is a MUST. The role will include, but not limited to; evolving the technical process, building operational capability, managing and hiring team, involved at a high level overviewing policy/playbooks, fine turning of the go-to-market collateral etc.
-
- Contact 12 month- Security Operations- Tanium Engineer / Analyst.
- United Kingdom
- Dependent on experience
-
Security Operations engineer / Analyst with Tanium for a 12 month contract. Experience configuring using, managing, supporting troubleshooting Tanium's suite of end point solutions is essential. The opportunity is due to a client expanding its international capability to a follow the sun model. To be involved in spinning up a European capability. Based in the UK. English essential and ideally being fluent in French.