Phishers abuse CrowdStrike brand targeting job seekers with cryptominer

Share:

image 14

CrowdStrike warns of a phishing campaign that uses its recruitment branding to trick recipients into downloading a fake application, which finally installs the XMRig cryptominer.

CrowdStrike discovered a phishing campaign using its recruitment branding to trick recipients into downloading a fake application, which acts as a downloader for the XMRig cryptominer.

The cybersecurity firm discovered the campaign on January 7, 2025, the company discovered that threat actors used false offers of employment with CrowdStrike.

“On January 7, 2025, CrowdStrike identified a phishing campaign exploiting its recruitment branding to deliver malware disguised as an “employee CRM application.” The attack begins with a phishing email impersonating CrowdStrike recruitment, directing recipients to a malicious website.” reads the report published by CrowdStrike. “Victims are prompted to download and run a fake application, which serves as a downloader for the cryptominer XMRig.”

CrowdStrike warns of a phishing campaign cryptominer

The email tricks recipients by claiming they have been selected for a junior developer role and must join a recruitment call by downloading a CRM tool via an embedded link. The phishing message directs the victims to a malicious website that appears to offer download options for both Windows and macOS.

Regardless of the chosen option, a Windows executable written in Rust is downloaded. The application serves as a downloader for XMRig, researchers noticed it supports evasion mechanisms.

Evasion checks supported by the malicious code include detecting debuggers, verifying active processes, checking CPU core count, and scanning for malware analysis tools. If the environment passes these checks, it displays a fake error message before proceeding. The executable then downloads a text file containing XMRig configuration details to initiate mining activities.

“Individuals in the recruitment process should verify the authenticity of CrowdStrike communications and avoid downloading unsolicited files.” concludes the report. “Outside of this campaign, we are aware of scams involving false offers of employment with CrowdStrike. Fraudulent interviews and job offers use fake websites, email addresses, group chats and text messages. We do not interview prospective candidates via instant message or group chat, nor do we require candidates to purchase products or services, or process payments on our behalf, as a condition of any employment offer. And, in reference to the campaign detailed above, we do not ask candidates to download software for interviews.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:05 pm, Jun 8, 2025
weather icon 16°C
L: 15° | H: 18°
clear sky
Humidity: 53 %
Pressure: 1018 mb
Wind: 8 mph NNW
Wind Gust: 16 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 2%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:14 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 11 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 18°°C 0 mm 0% 8 mph 86 % 1022 mb 0 mm/h
Tue Jun 10 10:00 pm
weather icon
12° | 21°°C 0.97 mm 97% 10 mph 85 % 1019 mb 0 mm/h
Wed Jun 11 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 10 mph 91 % 1019 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 12 mph 82 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
16° | 16°°C 0 mm 0% 11 mph 54 % 1018 mb 0 mm/h
Today 4:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 53 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
17° | 18°°C 0 mm 0% 10 mph 55 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 13°°C 0 mm 0% 7 mph 80 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 5 mph 86 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 6 mph 78 % 1022 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 6 mph 60 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,437.23
0.25%
Ethereum(ETH)
€2,193.76
0.27%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€1.94
1.14%
Solana(SOL)
€130.60
-1.97%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.159768
-2.14%
Shiba Inu(SHIB)
€0.000011
-2.57%
Pepe(PEPE)
€0.000010
-0.81%
Peanut the Squirrel(PNUT)
€0.234364
7.64%
Scroll to Top