Phishers abuse CrowdStrike brand targeting job seekers with cryptominer

Share:

image 14

CrowdStrike warns of a phishing campaign that uses its recruitment branding to trick recipients into downloading a fake application, which finally installs the XMRig cryptominer.

CrowdStrike discovered a phishing campaign using its recruitment branding to trick recipients into downloading a fake application, which acts as a downloader for the XMRig cryptominer.

The cybersecurity firm discovered the campaign on January 7, 2025, the company discovered that threat actors used false offers of employment with CrowdStrike.

“On January 7, 2025, CrowdStrike identified a phishing campaign exploiting its recruitment branding to deliver malware disguised as an “employee CRM application.” The attack begins with a phishing email impersonating CrowdStrike recruitment, directing recipients to a malicious website.” reads the report published by CrowdStrike. “Victims are prompted to download and run a fake application, which serves as a downloader for the cryptominer XMRig.”

CrowdStrike warns of a phishing campaign cryptominer

The email tricks recipients by claiming they have been selected for a junior developer role and must join a recruitment call by downloading a CRM tool via an embedded link. The phishing message directs the victims to a malicious website that appears to offer download options for both Windows and macOS.

Regardless of the chosen option, a Windows executable written in Rust is downloaded. The application serves as a downloader for XMRig, researchers noticed it supports evasion mechanisms.

Evasion checks supported by the malicious code include detecting debuggers, verifying active processes, checking CPU core count, and scanning for malware analysis tools. If the environment passes these checks, it displays a fake error message before proceeding. The executable then downloads a text file containing XMRig configuration details to initiate mining activities.

“Individuals in the recruitment process should verify the authenticity of CrowdStrike communications and avoid downloading unsolicited files.” concludes the report. “Outside of this campaign, we are aware of scams involving false offers of employment with CrowdStrike. Fraudulent interviews and job offers use fake websites, email addresses, group chats and text messages. We do not interview prospective candidates via instant message or group chat, nor do we require candidates to purchase products or services, or process payments on our behalf, as a condition of any employment offer. And, in reference to the campaign detailed above, we do not ask candidates to download software for interviews.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:45 pm, Jan 15, 2025
weather icon 10°C
L: 9° | H: 10°
overcast clouds
Humidity: 91 %
Pressure: 1034 mb
Wind: 3 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:59 am
Sunset: 4:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 10°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 5 mph 92 % 1036 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 91 % 1033 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
1° | 6°°C 0 mm 0% 4 mph 94 % 1024 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 10°°C 0 mm 0% 2 mph 91 % 1034 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 9°°C 0 mm 0% 3 mph 93 % 1034 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 8°°C 0 mm 0% 2 mph 95 % 1034 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
8° | 8°°C 0 mm 0% 5 mph 80 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,742.84
2.35%
Ethereum(ETH)
€3,181.83
2.27%
XRP(XRP)
€2.78
11.37%
Tether(USDT)
€0.97
0.00%
Solana(SOL)
€186.79
2.48%
Dogecoin(DOGE)
€0.355389
4.87%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
1.87%
Pepe(PEPE)
€0.000017
2.34%
Peanut the Squirrel(PNUT)
€0.56
-9.04%
Scroll to Top