Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ResumeLooters

Description

Since the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites. The group employs a variety of simple techniques, including SQL injection and XSS. The threat actor attempted to insert XSS scripts into all available forms, aiming to execute it on the administrators’ device to obtain admin credentials. While the group was able to execute the XSS script on some visitors’ devices with administrative access, allowing ResumeLooters to steal the HTML code of the pages the victims were visiting, Group-IB did not find any confirmation of admin credential thefts.

AI Analysis

· 1 week ago

Executive Summary

ResumeLooters have emerged as a threat group actively compromising websites through SQL injection and XSS attacks since early 2023. Despite their efforts to steal admin credentials via malicious scripts, there’s no confirmed success yet. Their targeting suggests a focus on disrupting or damaging website operations.

Goals & Targeting

Their primary goal seems to be compromising websites likely for disruption or data collection. Targeted sectors and countries aren't specified beyond the 65 known compromises, suggesting a broad focus.

Enhanced Description

ResumeLooters have demonstrated basic attack techniques but show potential for escalation. They primarily use SQL injection and XSS to gain unauthorized access to websites. Group-IB's analysis found their scripts were injected into forms, aiming to execute on admin devices. Though no confirmed credential theft occurred, their pattern indicates ongoing efforts to compromise website security through vulnerabilities like insecure query parameters (T1567.001).

Key Capabilities

  • SQL injection attacks (T1567)
  • Cross-Site Scripting (XSS) (T1062)
  • Script injection for credential theft attempts
  • Potential lateral movement if admin access is achieved

MITRE ATT&CK Tactics

Reconnaissance
Network Access Exploitation

ATT&CK Techniques

T1567.001
T1062

Software / Tooling

Custom script injection tool

Campaigns & Victims

ResumeLooters has been active since early 2023, targeting websites with vulnerable forms. Campaign patterns suggest an attempt to compromise admin access but no confirmed success yet. The group likely develops its capabilities over time.

IOC Patterns

  • Spear-phishing emails requesting website login credentials
  • Unusual web requests indicative of SQL injection attempts
  • Injection scripts in web form fields

Recommended Actions

  • Patch websites for SQL injection and XSS vulnerabilities.
  • Implement a Web Application Firewall (WAF).
  • Monitor server logs for script injection attempts.
  • Educate staff on phishing attacks.

Suggested Tags

Web-Attacks
APT group
Malware

Confidence Assessment

Low confidence due to limited data about their exact motives and future actions beyond initial campaigns. Their evolution from simple to more advanced techniques is an unknown.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Data Exfiltration
Web-Attacks
APT group
Malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.