logo

Beware! Fake Crowdstrike Recruitment Emails Spread Cryptominer Malware

ID: 10214bb7-4e8c-5143-aeca-06772426054e

STIX ID: report--10214bb7-4e8c-5143-aeca-06772426054e

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2025-01-10

Date Updated: 2026-04-22

Author: Divya

...
...

CrowdStrike uncovered a recruitment-themed phishing campaign that impersonates its hiring team to trick victims into downloading a fake “employee CRM” application; the delivered Windows executable (written in Rust) functions as a downloader for the XMRig cryptominer, uses multiple environment-evasion checks (IsDebuggerPresent, process counts, CPU cores, process scanning), fetches configuration and XMRig from the web/GitHub, and establishes persistence via a startup batch script and registry changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.