Info-stealer malware referenced in the source content as being delivered through online job scam campaigns disguised as interview software, job application materials, or fake application downloads. The malware is described as targeting browser credentials and authentication tokens, and is associated with credential harvesting activity that can enable financial theft, identity fraud, credential stuffing, business email compromise, supply chain attacks, and potential corporate network infiltration. The content states that these infections may occur on unmanaged personal devices that later connect to enterprise environments, creating an enterprise security risk that traditional controls may miss because personal devices are often not covered by EDR, network monitoring cannot detect malware installed before connection, and DLP does not flag data submitted to fake recruiters. The article attributes the warning to a recent Google advisory about scammers embedding remote access Trojans and info-stealers in fake recruitment workflows. No specific threat actor, malware family alias, or technical indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Info-stealers are malware designed to extract browser credentials, authentication tokens, and data from password managers. In the context of job scams, they are delivered as disguised application materials and are used to harvest sensitive information from victims, which can then be used for credential stuffing, business email compromise, and other attacks.
Info-stealers are malware designed to extract browser credentials, authentication tokens, and data from password managers. In the context of job scams, they are delivered as disguised application materials and are used to harvest sensitive information from victims, which can then be used for credential stuffing, business email compromise, and other attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.