Beware! Fake Crowdstrike Recruitment Emails Spread Cryptominer Malware
ID: 10214bb7-4e8c-5143-aeca-06772426054e
STIX ID: report--10214bb7-4e8c-5143-aeca-06772426054e
Feed Name: GBHackers
CrowdStrike uncovered a recruitment-themed phishing campaign that impersonates its hiring team to trick victims into downloading a fake “employee CRM” application; the delivered Windows executable (written in Rust) functions as a downloader for the XMRig cryptominer, uses multiple environment-evasion checks (IsDebuggerPresent, process counts, CPU cores, process scanning), fetches configuration and XMRig from the web/GitHub, and establishes persistence via a startup batch script and registry changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
