Fake CrowdStrike job offer emails target devs with crypto miners

Share:

CrowdStrike is warning that a phishing campaign is impersonating the cybersecurity company in fake job offer emails to trick targets into infecting themselves with a Monero cryptocurrency miner (XMRig).

The company discovered the malicious campaign on January 7, 2025, and based on the phishing email’s content, it likely didn’t start much earlier.

The attack starts with a phishing email sent to job seekers, supposedly from a CrowdStrike employment agent, thanking them for applying for a developer position at the company.

Email sent to targets
Email sent to job candidates
Source: Crowdstrike
The email directs targets to download a supposed “employee CRM application” from a website designed to appear like a legitimate Crowdstrike portal.

This is supposedly part of the company’s effort to “streamline their onboarding process by rolling out a new applicant CRM app.”

Candidates clicking on the embedded link are taken to a website (“cscrm-hiring[.]com”) that contains links to download the said application for Windows or macOS.

Malicious website abusing the Crowdstrike brand
Malicious website abusing the Crowdstrike brand
Source: Crowdstrike
The downloaded tool performs sandbox checks before fetching additional payloads to ensure it’s not running in an analysis environment, like checking the process number, CPU core count, and the presence of debuggers.Once those checks are over and the result is negative, aka the victim qualifies for infection, the application generates a bogus error message informing that the installer file is probably corrupt.

Fake error message
Fake error message
Source: Crowdstrike
In the background, the downloader retrieves a configuration text file containing the required parameters for running XMRig.

It then downloads a ZIP archive containing the miner from a GitHub repository and unzips the files in ‘%TEMP%\System\.’

The miner is set to run in the background, consuming minimal processing power (max 10%) to avoid detection.

A batch script is added in the Start Menu Startup directory for persistence between reboots, while a logon autostart key is also written in the registry.

More details on the campaign and indicators of compromise associated with it can be found in Crowdstrike’s report.

Job seekers should always confirm they are speaking to an actual recruiter by verifying the email address belongs to the official company domain and by contacting that person from the official firm’s page.

Beware of urgent or unusual requests, offers that are too good to be true, or invitations to download executable files on your computer, supposedly required for recruitment.

Employers rarely, if ever, require candidates to download third-party applications as part of an interview process and never request upfront payments.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:57 pm, Jun 30, 2025
weather icon 24°C
L: 23° | H: 25°
clear sky
Humidity: 67 %
Pressure: 1015 mb
Wind: 2 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
23° | 25°°C 0 mm 0% 11 mph 67 % 1015 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
19° | 26°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 7 mph 53 % 1029 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 10 mph 47 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 21°°C 1 mm 100% 12 mph 90 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
22° | 24°°C 0 mm 0% 3 mph 67 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
21° | 23°°C 0 mm 0% 3 mph 66 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
22° | 23°°C 0 mm 0% 5 mph 63 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
28° | 28°°C 0 mm 0% 3 mph 44 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
34° | 34°°C 0 mm 0% 8 mph 26 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
32° | 32°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
25° | 25°°C 0 mm 0% 8 mph 46 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,726.36
0.08%
Ethereum(ETH)
€2,141.69
2.99%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.95
4.59%
Solana(SOL)
€134.28
4.10%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142338
1.58%
Shiba Inu(SHIB)
€0.000010
0.00%
Pepe(PEPE)
€0.000009
2.69%
Scroll to Top