Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

A sophisticated phishing campaign dubbed FAUX#ELEVATE is targeting French-speaking enterprises with malicious VBScript files disguised as resumes to steal credentials and mine Monero.
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers.
The campaign, codenamed FAUX#ELEVATE, uses highly obfuscated VBScript files disguised as resume/CV documents. Once executed, the malware deploys a multi-purpose toolkit that combines credential theft, data exfiltration, and Monero cryptocurrency mining.
Notably, the script contains over 224,000 lines, but only 266 lines are actual executable code, with the rest being junk comments to inflate the file size to 9.7MB and evade detection. It also uses a WMI-based check to ensure it only infects domain-joined enterprise machines, ignoring standalone home systems.
The attack leverages legitimate services like Dropbox for hosting payloads and mail.ru for data exfiltration. According to Securonix, the entire infection chain completes in approximately 25 seconds, making it a significant threat to enterprise security teams due to its speed and selective targeting.
Source: The Hacker News















