Hackers use booby-trapped resumes. Steal credentials, deploy crypto miner in company systems.
Mar 24, 2026 // 19:43 - Tristan Wall


A current phishing scheme is targeting French-speaking businesses using deceptive job applications that install cryptocurrency miners and steal information.

“The campaign uses heavily disguised VBScript files posing as resumes/CVs, which are distributed through phishing emails,” stated Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee in a report shared with The Hacker News.

“Once activated, the malware deploys a comprehensive toolset that combines stealing login details, copying data, and mining Monero cryptocurrency to maximize profits.”

The cybersecurity firm has labeled this activity FAUX#ELEVATE. The campaign stands out due to its misuse of legitimate services and infrastructure, such as using Dropbox to store malicious files, Moroccan WordPress sites to host command-and-control (C2) configurations, and mail[.]ru SMTP infrastructure to extract stolen browser logins and desktop files.

This is an example of an attack that utilizes existing system tools to avoid detection, making it harder for defense mechanisms to identify and prevent intrusion without raising suspicion.

The initial file that starts the infection is a Visual Basic Script (VBScript) that, when opened, shows a fake error message in French, tricking recipients into believing the file is damaged. However, in the background, the highly obscured script performs multiple checks to avoid detection by sandbox environments and enters a continuous User Account Control (UAC) loop, prompting users to run it with administrator rights.

Interestingly, only 266 lines of the script’s 224,471 lines contain actual executable code. The remaining lines are filled with meaningless comments containing random English sentences, increasing the file size to 9.7MB.

“The malware also uses a domain-join check using WMI [Windows Management Instrumentation], ensuring that malicious software is only delivered on company computers, completely excluding personal home systems,” the researchers explained.

Once the initial program gains administrative access, it quickly disables security features and hides its actions by setting up Microsoft Defender exclusion paths for all main drive letters (from C to I), turning off UAC through a Windows Registry modification, and deleting itself.

The initial program is also responsible for downloading two separate password-protected 7-Zip archives from Dropbox –

  • gmail2.7z, which includes various programs to steal data and mine cryptocurrency
  • gmail_ma.7z, which includes tools for maintaining persistence and removing traces

Among the tools used to facilitate credential theft is a component that utilizes the ChromElevator project to steal sensitive data from Chromium-based browsers by bypassing app-bound encryption (ABE) protections. Some of the other tools include –

  • mozilla.vbs, a VBScript malware for stealing Mozilla Firefox profile information and login details
  • walls.vbs, a VBScript payload for copying desktop files
  • mservice.exe, an XMRig cryptocurrency miner that starts after retrieving the mining settings from a compromised Moroccan WordPress site
  • WinRing0x64.sys, a legitimate Windows kernel driver used to maximize the CPU’s mining performance
  • RuntimeHost.exe, a persistent Trojan component that changes Windows Firewall rules and periodically communicates with a C2 server

The browser data is sent using two different mail[.]ru sender accounts (“[email protected]” and “[email protected]”) that share the same password over SMTP to another email address controlled by the attacker (“[email protected]”).

After stealing credentials and copying data, the attack chain aggressively removes all installed tools to minimize traces, leaving only the miner and trojan behind.

“The FAUX#ELEVATE campaign is a well-structured, multi-stage attack operation that combines several notable techniques into a single infection process,” Securonix stated.

“What makes this campaign particularly dangerous for enterprise security teams is the speed of execution, the complete infection happens in about 25 seconds from the moment the VBS is executed to when the login information is copied, and the selective targeting of computers connected to a domain, ensuring maximum profit through stealing company login details and persistent resource hijacking.”

#booby-trapped  #company  #credentials  #crypto  #deploy  #hackers  #miner  #news  #resumes.  #steal  #systems  #use   —   News