Attention German HR departments: You may want to cross off a certain "Eva Richter" from your list of employment candidates. Especially because her so-called résumé actually infects recipients with the destructive Ordinypt Wiper malware, according to a new report.

The fake résumé phishing campaign began on Sept. 11 and is specifically aimed at German-speaking employers, Bleeping Computer reported this past weekend. The campaign sends an email that appears to be a job application, replete with photo and résumé of one Eva Richter. But in reality, the photo is a random stock photo and the résumé is a PDF file that delivers Ordinypt.

Historically, Ordinypt targets Germans acts very much like a typical ransomware program. It maliciously encrypts victims' files and demands a payment via a Tor site to restore the files. However, in this instance, even if the victim pays up, the files remain useless because they are overwritten with random characters.

Please register to continue.

Already registered? Log in.

Once you register, you'll receive:

  • News analysis

    The context and insight you need to stay abreast of the most important developments in cybersecurity. CISO and practitioner perspectives; strategy and tactics; solutions and innovation; policy and regulation.

  • Archives

    Unlimited access to nearly 20 years of SC Media industry analysis and news-you-can-use.

  • Daily Newswire

    SC Media’s essential morning briefing for cybersecurity professionals.

  • Learning Express

    One-click access to our extensive program of virtual events, with convenient calendar reminders and ability to earn CISSP credits.