Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
The deployment of cryptocurrency miners and information thieves is the result of a continuous phishing campaign that targets French-speaking corporate environments with phony resumes.
According to a study published with The Hacker News by Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee, the campaign leverages highly obfuscated VBScript files that are sent through phishing emails under the appearance of resume/CV materials.
In order to maximize profits, the malware uses a multifunctional toolkit that includes data exfiltration, credential theft, and Monero cryptocurrency mining.
The cybersecurity firm has dubbed the action FAUX#ELEVATE. The campaign is notable for abusing reputable infrastructure and services, including mail, Moroccan WordPress websites h...

