<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j" -->

---
title: BlackSanta malware uses fake resumes to kill EDR and...
description: A Russian-speaking threat actor has been targeting corporate HR and recruiting staff for over a year with spear-phishing emails disguised as fake job...
canonical: https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: BlackSanta malware uses fake resumes to kill EDR and exfiltrate data from HR teams | daily.dev
og:description: A Russian-speaking threat actor has been targeting corporate HR and recruiting staff for over a year with spear-phishing emails disguised as fake job...
og:url: https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j
og:image: https://api.daily.dev/og/posts/8CROJKF4J.png
og:image:alt: BlackSanta malware uses fake resumes to kill EDR and exfiltrate data from HR teams
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# BlackSanta malware uses fake resumes to kill EDR and exfiltrate data from HR teams

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A Russian-speaking threat actor has been targeting corporate HR and recruiting staff for over a year with spear-phishing emails disguised as fake job applications. The attack chain begins with an ISO image delivered via cloud storage, which auto-executes a malicious LNK shortcut, runs obfuscated PowerShell, and extracts a payload hidden in a steganographic image via DLL sideloading. The core component, BlackSanta, is an EDR killer that uses the Bring Your Own Vulnerable Driver (BYOVD) technique to load a flawed kernel driver, disable antivirus, EDR agents, Microsoft Defender, and system logging, then exfiltrates files and cryptocurrency artifacts over HTTPS. HR teams are targeted because opening files from strangers is routine for recruiters, yet they often receive less security attention than finance or IT. Recommended mitigations include endpoint hardening on HR workstations, attachment type controls, and security awareness training for recruiting staff.

## Content

A Russian-speaking threat actor has been running a spear-phishing campaign for over a year, targeting corporate HR and recruiting staff with fake job applications. The campaign has stayed largely under the radar thanks to a technically sophisticated attack chain that ultimately disables endpoint defenses before stealing data.

## How the attack works

The initial lure is an ISO disk image disguised as a resume, delivered via legitimate cloud storage services. When a recruiter opens it, the ISO mounts and automatically executes a malicious LNK shortcut. That shortcut runs obfuscated PowerShell commands, which extract a hidden payload from a steganographic image file. A legitimate signed application then sideloads a malicious DLL, completing the installation.

The standout component is a module researchers have named **BlackSanta** - an EDR killer that uses the Bring Your Own Vulnerable Driver (BYOVD) technique. It loads a legitimate but flawed kernel driver to gain low-level system access, then uses that access to disable antivirus software, EDR agents, Microsoft Defender, and system logging. Once defenses are neutralized, the malware exfiltrates sensitive files and cryptocurrency artifacts over encrypted HTTPS to a command-and-control server.

The campaign has avoided detection through a combination of runtime encryption, sandbox evasion, and kernel-level manipulation.

## Why HR is the target

Recruiters routinely download files from strangers under time pressure - it's just part of the job. That workflow makes HR teams an attractive target that often doesn't get the same defensive attention as finance or IT systems. Researchers at Aryaka, who analyzed the campaign, argue that should change.

Recommended mitigations include endpoint hardening on HR workstations, controls on attachment types that can be opened, and security awareness training specifically for recruiting teams. The same rigor applied to finance and IT administrative functions needs to extend to anyone whose job involves opening files from unknown senders.

## Similar posts on daily.dev

- [Resumés with malicious ISO attachments are circulating, says Aryaka](https://daily.dev/posts/resum-s-with-malicious-iso-attachments-are-circulating-says-aryaka-pbkfyg6n8) · CSO Online · 1 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"BlackSanta malware uses fake resumes to kill EDR and exfiltrate data from HR teams","url":"https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j"},"datePublished":"2026-03-11T17:40:47.354Z","dateModified":"2026-03-11T17:41:11.338Z","description":"A Russian-speaking threat actor has been targeting corporate HR and recruiting staff for over a year with spear-phishing emails disguised as fake job...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/af2769f83d73a806ed16ffd25c0e530c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/af2769f83d73a806ed16ffd25c0e530c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/blacksanta-malware-uses-fake-resumes-to-kill-edr-and-exfiltrate-data-from-hr-teams-8crojkf4j","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,powershell","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"BlackSanta malware uses fake resumes to kill EDR and exfiltrate data from HR teams"}]}
```

