logo

Recruitment Phishing Scam Imitates CrowdStrike Hiring Process

ID: a193abca-3a2b-54bf-ac23-6d9bc598efb0

STIX ID: report--a193abca-3a2b-54bf-ac23-6d9bc598efb0

Feed Name: Crowdstrike Blog

Threat Score
50/100

Date Published: 2025-01-08

Date Updated: 2026-04-27

Author: Counter Adversary Operations

...
...

This CrowdStrike report details a phishing campaign using a fake recruitment CRM (cscrm-hiring.com) that distributes a malicious installer which fetches XMRig and a configuration file, installs persistent copies of the miner and downloader (via file drops, a startup batch, and a Run registry entry), and connects to an attacker-controlled mining pool; the report provides network and host IOCs (domains, IPs, URLs, SHA-256 hashes, file paths, registry keys) and advises vigilance, employee education, and endpoint/network monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.