<ul data-eligibleForWebStory="true">Hackers are using fake jobseeker personas to spread malware targeting recruiters and HR managers.DomainTools identified FIN6 creating fake LinkedIn profiles and resume websites anonymously hosted on AWS.The hackers build rapport with targets before sharing resume websites that filter visitors based on OS and connection type.Recruiters served a .ZIP archive, thinking it contains a resume, but it actually drops the 'More Eggs' backdoor.The 'More Eggs' malware can execute commands, steal credentials, deliver payloads, and use social engineering.AWS acknowledges the findings and stresses that such campaigns violate its terms of service.