Phishers abuse CrowdStrike brand targeting job seekers with cryptominer

Teilen:

image 14

CrowdStrike warns of a phishing campaign that uses its recruitment branding to trick recipients into downloading a fake application, which finally installs the XMRig cryptominer.

CrowdStrike discovered a phishing campaign using its recruitment branding to trick recipients into downloading a fake application, which acts as a downloader for the XMRig cryptominer.

The cybersecurity firm discovered the campaign on January 7, 2025, the company discovered that threat actors used false offers of employment with CrowdStrike.

“On January 7, 2025, CrowdStrike identified a phishing campaign exploiting its recruitment branding to deliver malware disguised as an “employee CRM application.” The attack begins with a phishing email impersonating CrowdStrike recruitment, directing recipients to a malicious website.” reads the Bericht published by CrowdStrike. “Victims are prompted to download and run a fake application, which serves as a downloader for the cryptominer XMRig.”

CrowdStrike warns of a phishing campaign cryptominer

The email tricks recipients by claiming they have been selected for a junior developer role and must join a recruitment call by downloading a CRM tool via an embedded link. The phishing message directs the victims to a malicious website that appears to offer download options for both Windows and macOS.

Regardless of the chosen option, a Windows executable written in Rust is downloaded. The application serves as a downloader for XMRig, researchers noticed it supports evasion mechanisms.

Evasion checks supported by the malicious code include detecting debuggers, verifying active processes, checking CPU core count, and scanning for malware analysis tools. If the environment passes these checks, it displays a fake error message before proceeding. The executable then downloads a text file containing XMRig configuration details to initiate mining activities.

“Individuals in the recruitment process should verify the authenticity of CrowdStrike communications and avoid downloading unsolicited files.” concludes the report. “Outside of this campaign, we are aware of scams involving false offers of employment with CrowdStrike. Fraudulent interviews and job offers use fake websites, email addresses, group chats and text messages. We do not interview prospective candidates via instant message or group chat, nor do we require candidates to purchase products or services, or process payments on our behalf, as a condition of any employment offer. And, in reference to the campaign detailed above, we do not ask candidates to download software for interviews.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:31 pm, Jan. 15, 2025
Wetter-Symbol 9°C
L: 9° | H: 10°
overcast clouds
Luftfeuchtigkeit: 91 %
Druck: 1034 mb
Wind: 3 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:59 am
Sonnenuntergang: 4:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 9°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Fr. Jan. 17 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 5 mph 92 % 1036 mb 0 mm/h
Sa. Jan. 18 9:00 pm
Wetter-Symbol
2° | 6°°C 0 mm 0% 4 mph 91 % 1033 mb 0 mm/h
So. Jan. 19 9:00 pm
Wetter-Symbol
1° | 6°°C 0 mm 0% 4 mph 94 % 1024 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 2 mph 91 % 1034 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 9°°C 0 mm 0% 3 mph 93 % 1034 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 7°°C 0 mm 0% 2 mph 95 % 1034 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 5 mph 80 % 1034 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,118.20
2.35%
Ethereum(ETH)
€3,195.62
2.26%
XRP(XRP)
€2.76
10.37%
Fesseln(USDT)
€0.97
0.01%
Solana(SOL)
€188.56
2.69%
Dogecoin(DOGE)
€0.354668
3.64%
USDC(USDC)
€0.97
0.01%
Shiba Inu(SHIB)
€0.000021
2.06%
Pepe(PEPE)
€0.000017
2.86%
Peanut das Eichhörnchen(PNUT)
€0.55
-8.54%
Nach oben scrollen