Cybercriminals are impersonating CrowdStrike recruiters to distribute a cryptominer on victim devices.
CrowdStrike said it identified phishing campaign exploiting its recruitment branding on January 7.
The campaign starts with a phishing email, which purports to part of the cybersecurity firm’s recruitment process. The email invites the target to schedule an interview for a junior developer role.
The email contains a link claiming to take the recipient to a site where they can schedule their interview.
This routes the victim to a malicious phishing site containing download links for a fake “CRM application,” with separate links for Windows and macOS.
No tags.