Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Resume Phishing Campaign Harvests Enterprise Credentials and Deploys Crypto Miners in French‑Speaking Corporations

A targeted phishing campaign uses counterfeit résumé documents to deliver malicious VBScript, stealing enterprise credentials and installing cryptocurrency miners in French‑speaking corporate environments. The technique bypasses traditional email defenses and poses a significant third‑party risk through credential compromise and resource‑draining malware.

LiveThreat™ Intelligence · 📅 March 25, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Fake Resume Phishing Campaign Harvests Enterprise Credentials and Deploys Crypto Miners in French‑Speaking Corporations

What Happened — A phishing operation targeting French‑speaking corporate users distributes malicious VBScript files masquerading as résumé/CV documents. When opened, the script steals enterprise credentials and installs a cryptocurrency miner alongside information‑stealing payloads.

Why It Matters for TPRM —

  • Credential theft can give attackers lateral movement into third‑party environments.
  • Crypto‑miner deployment consumes resources, impacting service availability and cost.
  • The use of seemingly innocuous résumé files increases the likelihood of successful compromise across multiple vendors.

Who Is Affected — Enterprises operating in French‑speaking regions across technology, finance, manufacturing, and professional services that accept résumé attachments.

Recommended Actions —

  • Review and tighten email filtering rules for attachment types, especially VBScript and Office files.
  • Enforce multi‑factor authentication (MFA) for all privileged accounts.
  • Conduct phishing awareness training focused on social‑engineering tactics involving recruitment materials.
  • Verify that endpoint detection and response (EDR) solutions can detect and block malicious script execution.

Technical Notes — Attack vector: phishing with malicious VBScript disguised as résumé/CV. No specific CVE cited. Data types at risk: usernames, passwords, domain credentials. Malware payloads include credential harvesters and cryptomining miners (likely XMRig or similar). Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/03/hackers-use-fake-resumes-to-steal.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →