How a fake AI recruiter delivers five staged malware disguised as a dream job
2025-10-20 • Deriv Tech •
A fake LinkedIn recruiter persona for DLMind steered developers toward a private GitHub assessment, AI-Healthcare, whose startup path fetched a staged JavaScript payload from loopsoft[.]tech:6168/defy/v8. The BeaverTail-style chain is described as a cross-platform infostealer and Socket.IO backdoor with VM checks, clipboard monitoring, keylogging, screenshots, file scanning, remote command execution, and Python payload deployment. It targeted browser credentials, macOS Keychain data, developer secrets, environment files, and cryptocurrency wallet artifacts across major browsers and wallet extensions. The decoded configuration exposed C2 and exfiltration infrastructure including 172[.]86[.]89[.]10:4382 and 88[.]218[.]0[.]78:1224, showing a recruitment lure built to compromise developer systems and steal high-value credentials.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| HASH | e43673a2a77ed68fa6e8074167350f8f | 2025-10-20 | 2026-02-03 |
| HASH | 351535afd2d98b9a3a0e14905a60a345 | 2025-10-20 | 2026-02-03 |
| HASH | 967adedce518105664c46e21fd4edb0… | 2025-10-20 | 2026-02-03 |
| IPv4 | 88.218.0.78 | 2025-10-20 | 2026-01-21 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| HASH | 99502507bfa92aee6d6b02203464104… | 2025-10-20 | 2025-10-20 |
| HASH | 3e5fd7fdc21c6cfd419cc84fa67b869e | 2025-10-20 | 2025-10-20 |
| HASH | ffed818b35b249db723741d3ec1cb7b… | 2025-10-20 | 2025-10-20 |
| HASH | 9daa4de89ea95bf5f7f97815ecee0d7… | 2025-10-20 | 2025-10-20 |
| HASH | 006c6a04a741ba75e66d460b441c898… | 2025-10-20 | 2025-10-20 |
| HASH | b59187e77c19f5fcd9fdb14663fbdd9… | 2025-10-20 | 2025-10-20 |
| URL | http://loopsoft.tech:6168/defy/… | 2025-10-20 | 2025-10-20 |
| IPv4 | 172.86.89.10 | 2025-10-20 | 2025-10-20 |
| DOMAIN | loopsoft.tech | 2025-10-10 | 2025-10-20 |