Phishers abuse CrowdStrike brand targeting job seekers with cryptominer

Share:

image 14

CrowdStrike warns of a phishing campaign that uses its recruitment branding to trick recipients into downloading a fake application, which finally installs the XMRig cryptominer.

CrowdStrike discovered a phishing campaign using its recruitment branding to trick recipients into downloading a fake application, which acts as a downloader for the XMRig cryptominer.

The cybersecurity firm discovered the campaign on January 7, 2025, the company discovered that threat actors used false offers of employment with CrowdStrike.

“On January 7, 2025, CrowdStrike identified a phishing campaign exploiting its recruitment branding to deliver malware disguised as an “employee CRM application.” The attack begins with a phishing email impersonating CrowdStrike recruitment, directing recipients to a malicious website.” reads the report published by CrowdStrike. “Victims are prompted to download and run a fake application, which serves as a downloader for the cryptominer XMRig.”

CrowdStrike warns of a phishing campaign cryptominer

The email tricks recipients by claiming they have been selected for a junior developer role and must join a recruitment call by downloading a CRM tool via an embedded link. The phishing message directs the victims to a malicious website that appears to offer download options for both Windows and macOS.

Regardless of the chosen option, a Windows executable written in Rust is downloaded. The application serves as a downloader for XMRig, researchers noticed it supports evasion mechanisms.

Evasion checks supported by the malicious code include detecting debuggers, verifying active processes, checking CPU core count, and scanning for malware analysis tools. If the environment passes these checks, it displays a fake error message before proceeding. The executable then downloads a text file containing XMRig configuration details to initiate mining activities.

“Individuals in the recruitment process should verify the authenticity of CrowdStrike communications and avoid downloading unsolicited files.” concludes the report. “Outside of this campaign, we are aware of scams involving false offers of employment with CrowdStrike. Fraudulent interviews and job offers use fake websites, email addresses, group chats and text messages. We do not interview prospective candidates via instant message or group chat, nor do we require candidates to purchase products or services, or process payments on our behalf, as a condition of any employment offer. And, in reference to the campaign detailed above, we do not ask candidates to download software for interviews.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:04 pm, Mar 27, 2025
weather icon 15°C
L: 15° | H: 15°
clear sky
Humidity: 63 %
Pressure: 1017 mb
Wind: 10 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 6%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:46 am
Sunset: 6:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 14°°C 0 mm 0% 7 mph 83 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sat Mar 29 9:00 pm
weather icon
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
Sun Mar 30 9:00 pm
weather icon
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mon Mar 31 9:00 pm
weather icon
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
weather icon
14° | 14°°C 0 mm 0% 7 mph 64 % 1017 mb 0 mm/h
Today 9:00 pm
weather icon
9° | 9°°C 0 mm 0% 7 mph 83 % 1017 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
weather icon
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
weather icon
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€80,714.95
0.27%
Ethereum(ETH)
€1,861.03
-0.35%
Tether(USDT)
€0.93
-0.03%
XRP(XRP)
€2.17
-2.63%
Solana(SOL)
€128.14
-0.81%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.178412
-2.01%
Shiba Inu(SHIB)
€0.000013
-2.31%
Pepe(PEPE)
€0.000008
-1.84%
Peanut the Squirrel(PNUT)
€0.213778
7.85%
Scroll to Top