logo

Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

ID: a1982586-5c62-50e2-bc4d-41a927285587

STIX ID: report--a1982586-5c62-50e2-bc4d-41a927285587

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Securonix researchers describe the FAUX#ELEVATE campaign targeting French-speaking corporate environments via fake CVs: an obfuscated VBScript dropper tricks users with a bogus error message, escalates privileges with a persistent UAC loop on domain-joined machines, disables security controls (Defender exclusions, UAC changes), fetches passworded 7-Zip payloads from Dropbox, and deploys credential stealers, desktop exfiltration scripts, a persistent Trojan, and an XMRig Monero miner while using Moroccan WordPress sites and mail.ru SMTP for C2 and exfiltration; the operation performs aggressive cleanup to minimize forensic traces and completes the full chain in roughly 25 seconds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.