Analysis of LinkedIn Recruitment Phishing
2025-03-15 • Slowmist •
https://slowmist.medium.com/slowmist-analysis-of-linkedin-recruitment-phishing-4b4b55e02bf4
SlowMist analyzes a LinkedIn recruiting lure that pushed a blockchain engineer toward a Bitbucket project for a supposed Socifi game and staking platform. The repository hid a malicious payload far to the right of an otherwise normal-looking server.js line, then executed it when the victim ran npm start. Dynamic analysis captured C2 traffic to 216.173.115.200:1244, follow-on downloads such as test.js and Python payload components, and scripts intended to maintain persistence. The malware collected host and environment data, stole browser and wallet-extension material, looked for SSH private keys and saved credentials, and prepared for crypto-asset theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.179.135.133 | 2025-03-15 | 2026-01-21 |
| IPv4 | 45.59.163.56 | 2025-03-15 | 2026-01-21 |
| IPv4 | 216.173.115.200 | 2025-03-15 | 2026-01-21 |
| IPv4 | 5.135.5.48 | 2025-03-15 | 2025-03-15 |
| IPv4 | 45.59.1.2 | 2025-03-15 | 2025-03-15 |