How a fake AI recruiter delivers five staged malware disguised as a dream job

2025-10-20 Deriv Tech

https://medium.com/deriv-tech/how-a-fake-ai-recruiter-delivers-five-staged-malware-disguised-as-a-dream-job-64cc68fec263

Thumbnail for How a fake AI recruiter delivers five staged malware disguised as a dream job

A fake LinkedIn recruiter persona for DLMind steered developers toward a private GitHub assessment, AI-Healthcare, whose startup path fetched a staged JavaScript payload from loopsoft[.]tech:6168/defy/v8. The BeaverTail-style chain is described as a cross-platform infostealer and Socket.IO backdoor with VM checks, clipboard monitoring, keylogging, screenshots, file scanning, remote command execution, and Python payload deployment. It targeted browser credentials, macOS Keychain data, developer secrets, environment files, and cryptocurrency wallet artifacts across major browsers and wallet extensions. The decoded configuration exposed C2 and exfiltration infrastructure including 172[.]86[.]89[.]10:4382 and 88[.]218[.]0[.]78:1224, showing a recruitment lure built to compromise developer systems and steal high-value credentials.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
HASH e43673a2a77ed68fa6e8074167350f8f 2025-10-20 2026-02-03
HASH 351535afd2d98b9a3a0e14905a60a345 2025-10-20 2026-02-03
HASH 967adedce518105664c46e21fd4edb0… 2025-10-20 2026-02-03
IPv4 88.218.0.78 2025-10-20 2026-01-21
DOMAIN ip-api.com 2022-11-14 2026-01-21
HASH 99502507bfa92aee6d6b02203464104… 2025-10-20 2025-10-20
HASH 3e5fd7fdc21c6cfd419cc84fa67b869e 2025-10-20 2025-10-20
HASH ffed818b35b249db723741d3ec1cb7b… 2025-10-20 2025-10-20
HASH 9daa4de89ea95bf5f7f97815ecee0d7… 2025-10-20 2025-10-20
HASH 006c6a04a741ba75e66d460b441c898… 2025-10-20 2025-10-20
HASH b59187e77c19f5fcd9fdb14663fbdd9… 2025-10-20 2025-10-20
URL http://loopsoft.tech:6168/defy/… 2025-10-20 2025-10-20
IPv4 172.86.89.10 2025-10-20 2025-10-20
DOMAIN loopsoft.tech 2025-10-10 2025-10-20

Related Reports

« Back