Security reporting linked an Iranian APT33 phishing campaign to fake job offers designed to lure targets into opening malicious attachments and visiting job-themed infrastructure. The activity used employment-related domains including world-jobs.org and raytheonjobs.serveblog.net, along with a ZIP archive and a malicious VBE script, to support credential theft, information theft, and unauthorized remote access. Researchers said the campaign’s exact end goal was not fully confirmed, but the tradecraft matched earlier intrusion activity associated with Iranian operators.
Additional indicators and detection content tied the campaign to PoshC2 payloads, including JavaScript- and HTA-based artifacts, file hashes, and an IP-hosted malware download path. A published YARA rule was created to help defenders identify payloads consistent with the reported APT33 activity, while guidance urged organizations to block the listed domains, URLs, hashes, and source IPs and to warn users against interacting with unsolicited recruiting emails or attached files.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published the YARA rule "poshc2_apt_33_2019" to detect PoshC2 payloads associated with 2019 APT33 reporting. The rule included hashes, URLs, and job-themed domains tied to the campaign and referenced the earlier Rewterz reporting.
Rewterz published a threat alert describing a phishing campaign using fake job offers as lures and linked the activity to Iranian threat actor APT33. The report said the campaign could enable credential theft, information theft, and unauthorized remote access, and published related indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.