216.73.216.6

Recruitment Phishing Scam Imitates Hiring Process

· Published 10/01/2025 12:17 · Modified 10/01/2025 13:12

Export JSON

Essential information

Published
10/01/2025 12:17
Modified
10/01/2025 13:12
Tags
2025-01-10 cryptominer job seekers phishing recruitment social engineering
Related entities
5 observables, 10 techniques (mitre), 1 malware

Description

A sophisticated campaign has been discovered that exploits branding to deliver malware. The attack begins with a email impersonating a process, directing victims to a malicious website. Users are prompted to download a fake application, which serves as a downloader for the XMRig . The malware performs environment checks to evade detection, downloads configuration files and the XMRig executable, and establishes persistence through multiple methods. This campaign highlights the importance of vigilance against scams, particularly those targeting . Organizations are advised to educate employees on tactics, monitor for suspicious network traffic, and employ endpoint protection solutions to detect and block malicious activity.

External references