Recruitment Phishing Scam Imitates CrowdStrike Hiring Process
ID: a193abca-3a2b-54bf-ac23-6d9bc598efb0
STIX ID: report--a193abca-3a2b-54bf-ac23-6d9bc598efb0
Feed Name: Crowdstrike Blog
This CrowdStrike report details a phishing campaign using a fake recruitment CRM (cscrm-hiring.com) that distributes a malicious installer which fetches XMRig and a configuration file, installs persistent copies of the miner and downloader (via file drops, a startup batch, and a Run registry entry), and connects to an attacker-controlled mining pool; the report provides network and host IOCs (domains, IPs, URLs, SHA-256 hashes, file paths, registry keys) and advises vigilance, employee education, and endpoint/network monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
