Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
ID: a1982586-5c62-50e2-bc4d-41a927285587
STIX ID: report--a1982586-5c62-50e2-bc4d-41a927285587
Feed Name: The Hacker News
Securonix researchers describe the FAUX#ELEVATE campaign targeting French-speaking corporate environments via fake CVs: an obfuscated VBScript dropper tricks users with a bogus error message, escalates privileges with a persistent UAC loop on domain-joined machines, disables security controls (Defender exclusions, UAC changes), fetches passworded 7-Zip payloads from Dropbox, and deploys credential stealers, desktop exfiltration scripts, a persistent Trojan, and an XMRig Monero miner while using Moroccan WordPress sites and mail.ru SMTP for C2 and exfiltration; the operation performs aggressive cleanup to minimize forensic traces and completes the full chain in roughly 25 seconds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
