"I will *** your fish"

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
“I will *** your fish” 🐟
In mid-October, a cyber intelligence group detected phishing activity targeting HR departments in the construction sector.
The attackers sent emails purportedly from HeadHunter demanding verification of an account on a third-party website. The email and one-time code entered on that page were used to hijack the account, after which the victim lost access to it (screenshot 1).
The link leads to the phishing domain hhcasa.xyz, which is behind Cloudflare and registered through Ukraine’s main domain registrar nic.ua (screenshot 2).
The page has two interface states. When auth=1 is present, the main “successful step” scene is shown; when absent, an alternative is displayed (screenshots 3–4).
This separation is used to hide the page from individuals who were not on the distribution list.
🪞 The layout and static assets copy hh.ru: Google Fonts and the favicon from i.hh.ru are pulled into <head>, the logo and header replicate the style, and the navigation items are clickable and direct the user to the legitimate domain simferopol.hh.ru, creating the impression of a “clean” website. However, the navigation contains a “Зарегестрироваться” (Register) item with a spelling error, which serves as an indicator of website spoofing.
The phishing page imitates the “email → confirmation code” flow. The user enters an email, the script validates the format with a regular expression and makes a POST request, the body of which also includes a Base64-format token generated directly in the browser from the User-Agent, the current time, and a random string.
❗️ We note that in March of this year we already recorded a similar phishing campaign in the name of HeadHunter. Back then, the navigation also contained a “Зарегестрироваться” item with the same characteristic error, and with the same principle of account compromise: the “email → one-time code → account hijacking” flow followed by loss of access.
The attackers also collect telemetry. It is implemented by creating an Image object and assigning it a src so that the browser sends a GET request to an external address with domain and timestamp parameters (screenshot 5).
The purpose of collecting telemetry is utilitarian: the operator sees the visitor’s real IP and the time of visit to a specific domain, which may indicate that the operators have additional phishing domains.
The IP address 185.162.10.35, to which telemetry is sent, is in ASN 59729 (GREEN FLOID LLC). According to analysis and pDNS observations, other phishing domains are also and have previously been hosted on this IP, which, like hhcasa.xyz, were registered through nic.ua.
hhrunaх.xyz;
hscac.xyz;
hmnsc.xyz.
🖕 The phishing domain has anti-debugging. The script intercepts the context menu, selection and copying, and hotkey combinations typically used to open source code and DevTools: Ctrl+U, Ctrl+S, Ctrl+Shift+I/J/C, and F12. When a “forbidden” key is triggered, the page erases the contents of the body and overlays a black full-screen block with a message (screenshots 6–7).
There is nothing complex about the protection: it cannot detect open DevTools and does not hide source code outside the current document in any way. The simplest way to bypass it is to open DevTools through the browser menu before the page loads, or to disable JavaScript execution for this domain and reload the tab to capture the HTML and static resources.
In addition to comments in Russian in the code, a Ukrainian layout is left in the markup: the <html> tag has lang="ua" set, likely this attribute was set automatically when the template was generated and they simply forgot to change it.
📝 In the phishing email itself, the group used the HH logo, which was loaded from a GitHub repository (screenshot 8). The repository (screenshot 9) was created in October 2022 and contains phishing website projects, one of which contained a custom stealer wrapped in a protector. When launched, the malware steals cookies and “login — password” pairs, sending everything to the attacker’s Telegram channel.
The Telegram account to which the bot sends the stolen data also mimics a HeadHunter company employee (screenshot 10).









#TI #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



