Instead of a job—stolen data and money. Trojan stealer targeting macOS and Windows users conceals itself in fake online interview apps
ID: efd8462b-bab5-5ea9-a8a3-e3032cf1e28e
STIX ID: report--efd8462b-bab5-5ea9-a8a3-e3032cf1e28e
Feed Name: Dr.Web News
**JobStealer trojan distributed via fake interview video-conference apps**: Doctor Web describes JobStealer, a trojan masquerading as conferencing software downloaded from fraudulent sites (via a bash command or a .dmg) that collects crypto wallet browser extensions, cookies, saved passwords and bank cards, Telegram session files, macOS Notes, keychain evidence, and other system data before packaging and exfiltrating it to a C2 server; the report includes MITRE ATT&CK mappings and notes macOS and Windows variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
