A hacker group named ‘ResumeLooters’ has stolen the personal data of over two million job seekers after compromising 65 legitimate job listing and retail sites using SQL injection and cross-site scripting (XSS) attacks.
The attackers mainly focus on the Asia-Pacific (APAC ) region, targeting sites in Australia, Taiwan, China, Thailand, India, and Vietnam to steal job seeker’s details such as names, email addresses, phone numbers, employment history, education, and other relevant information.
According to Singapore-headquartered Group-IB, the ResumeLooters tried to sell the stolen data through Telegram channels.
The stolen files are estimated to contain 2,188,444 user data records, of which 510,259 have been taken from job search websites. Over two million unique email addresses are present within the dataset.
Group-IB also uncovered evidence of cross-site scripting (XSS) infections on at least four legitimate job search websites that are designed to load malicious scripts responsible for displaying phishing pages capable of harvesting administrator credentials.
ResumeLooters is the second hacking group after GambleForce that has been found staging SQL injection attacks in the APAC region since the latter’s public disclosure in late December 2023.
The modus operandi of ResumeLooters involves the use of the open-source sqlmap tool to carry out SQL injection attacks and drop and execute additional payloads such as the BeEF (short for Browser Exploitation Framework) penetration testing tool and rogue JavaScript code designed to gather sensitive data and redirect users to credential harvesting pages.
On analysis of the threat actor’s infrastructure, the presence of other tools like Metasploit, dirsearch, and xray, alongside a folder hosting the pilfered data were found.
The campaign appears to be financially motivated, as the ResumeLooters have set up two Telegram channels to sell the information.














Comments