Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS
ID: 03c5f276-60d4-5a51-be53-4217b5a99636
STIX ID: report--03c5f276-60d4-5a51-be53-4217b5a99636
Feed Name: HackRead
A campaign using fake job interview platforms (examples: Meetlab.io, Meetix.app, Carolla.app, Cloudproxy.link) lures victims to install JobStealer via malicious DMGs or Terminal copy-paste commands; the trojan targets Windows and macOS (with download pages observed for Linux/iOS/Android), harvests browser-stored crypto wallet extensions and credentials, Telegram sessions, Apple Notes and traces of hardware wallet software, then compresses and exfiltrates the data to attacker-controlled C2 servers—users are advised to avoid running unsolicited Terminal commands and download conferencing tools only from official vendor sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
