Analysis of LinkedIn Recruitment Phishing

2025-03-15 Slowmist

https://slowmist.medium.com/slowmist-analysis-of-linkedin-recruitment-phishing-4b4b55e02bf4

Thumbnail for Analysis of LinkedIn Recruitment Phishing

SlowMist analyzes a LinkedIn recruiting lure that pushed a blockchain engineer toward a Bitbucket project for a supposed Socifi game and staking platform. The repository hid a malicious payload far to the right of an otherwise normal-looking server.js line, then executed it when the victim ran npm start. Dynamic analysis captured C2 traffic to 216.173.115.200:1244, follow-on downloads such as test.js and Python payload components, and scripts intended to maintain persistence. The malware collected host and environment data, stole browser and wallet-extension material, looked for SSH private keys and saved credentials, and prepared for crypto-asset theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.179.135.133 2025-03-15 2026-01-21
IPv4 45.59.163.56 2025-03-15 2026-01-21
IPv4 216.173.115.200 2025-03-15 2026-01-21
IPv4 5.135.5.48 2025-03-15 2025-03-15
IPv4 45.59.1.2 2025-03-15 2025-03-15

Related Actors

Related Reports

« Back