Phishy Job Offers: How Fake CrowdStrike Emails Mine More Than Just Your Interest

CrowdStrike warns of a phishing scam where fake job offer emails lead candidates to download a “CRM app” that infects their devices with a Monero miner. Job seekers should verify recruiter identities and be cautious of downloads. Remember, if it sounds too good to be true, it probably involves cryptocurrency mining.

Pro Dashboard

Hot Take:

Looks like the only thing more ruthless than job hunting is the job hunter hunting you! Phishing scammers are at it again, and this time, they’ve dressed up as CrowdStrike to give job seekers the surprise of their lives. Who knew a fake job offer could lead to mining cryptocurrency? If you thought you were getting paid to work, think again. You’re just paying the electric bill for a Monero miner. Keep your CVs safe and your antivirus closer!

Key Points:

  • Phishing campaign uses fake CrowdStrike job offers to distribute XMRig miner.
  • Email directs victims to download a fake CRM app from a bogus website.
  • App employs sandbox checks to evade analysis before downloading the miner.
  • Miner consumes minimal CPU power to avoid detection, ensuring persistence.
  • Verifying recruiter identities and avoiding sketchy downloads is advised.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?