Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
On macOS, attackers use Terminal commands or fake DMG files to trick users into running the malware...
The attack begins with the threat actors contacting potential victims and offering them a particular job vacancy. They invite users to a job interview and provide them with links to websites for the online meeting “platforms”... The malicious program JobStealer, disguised as an online conferencing app, is downloaded from them.
The JobStealer trojan pilfers various confidential information, including data from almost 300 browser crypto wallet extensions... and cookie files.
Next, Mac.PWS.JobStealer.1 collects the following data: operating system version and computer ID... cookie files... Telegram messenger files... user notes... evidence that the crypto wallets Ledger Live and Trezor Suite are present in the system.
This data is packed into a ZIP archive and uploaded to the C2 server.
This data is packed into a ZIP archive and uploaded to the C2 server.
After collecting the information, the malware compresses the files into a ZIP archive and uploads them to a command and control server controlled by the attackers. Dr.Web mapped the malware activity to several MITRE ATT&CK techniques, including ... exfiltration through web services.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing trojan for macOS and Windows that is disguised as video-conferencing software in fake job interview lures and steals crypto-wallet extension data, Telegram files, browser-saved passwords, bank card data, and cookies.
A credential- and crypto-focused stealer trojan delivered through fake job interview lures and disguised as video conferencing software. It targets cryptocurrency wallet extensions, browser cookies, saved passwords, Telegram session files, sensitive files, and traces of hardware wallet software across Windows and macOS, with possible variants for Linux, iOS, and Android.
A credential- and crypto-stealing trojan delivered through fake job interview conferencing platforms. It targets Windows and macOS users, steals browser credentials, cookies, autofill payment data, Telegram session files, Apple Notes data, and cryptocurrency wallet information, then compresses and uploads the stolen data to attacker-controlled command-and-control servers.
Information-stealing trojan targeting macOS and Windows users, distributed via fake job interview/video conferencing websites. It steals crypto wallet data, browser cookies, saved passwords, bank card details, Telegram files, macOS Notes data, and checks for Ledger Live and Trezor Suite before archiving and exfiltrating the data to a C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.