New Trojan Targets Monster.com Users for Identity Theft

CUPERTINO, Calif. — Online job hunters using the Internet to seek out a new career direction should take added precautions if posting information to Monster.com is part of their strategy, according to information uncovered by security software vendor Symantec this week.

Symantec’s researchers have identified a new Trojan being employed to target users of Monster.com for identity theft, according to the company’s security response blog.

The Trojan in question has been dubbed Infostealer.Monstres, and although the exploit has been characterized by Symantec as “very low” risk, the amount of data already collected by the attackers behind the Trojan already is prodigious.

During their investigation, Symantec’s researchers noticed that the Trojan was uploading data to a remote server. When the team accessed the remote server, they found “over 1.6 million entries with personal information belonging to several hundred thousand people,” according to a post made to the security response blog by Symantec’s Amado Hidalgo.

Surprised that such a low-profile Trojan was used to attack so many people, the Symantec team dug around to discover how the data was obtained.

After discovering that connections were only being made to the sub-domains hiring.monster.com and recruiter.monster.com, the researchers concluded that the Trojan “appears to be using the (probably stolen) credentials of a number of recruiters to login to the website and perform searches for resumes of candidates located in certain countries or working in certain fields.”

According to Symantec, the Trojan functions by sending HTTP commands that navigate the Managed Folders section of the site. The Trojan then parses the output from a pop-up window that contains the profiles of the candidates that match the compromised recruiters’ saved searches.

Symantec’s researchers found that a wide range of personal details of the job candidates have been accessed, and then uploaded to the remote server that is controlled by the attackers. The personal details include the name, surname, email address, country, home address, work/mobile/home phone numbers and resume ID, according to the security response blog.

“Such a large database of highly personal information is a spammer’s dream,” Hidalgo wrote. “In fact, we found the Trojan can be instructed to send spam email using a mail template downloadable from the command & control server.”

Symantec has informed Monster.com of the compromised recruiter accounts so that the accounts can be disabled, Hidalgo said. Symantec also suggested that to reduce the risk of identity theft, users should limit the contact information they post on job-hunting sites, and never disclose information such as Social Security numbers, passport or driver’s license numbers, bank account information or other sensitive details.

For more information on the Infostealer.Monstres Trojan, see the Symantec advisory concerning the exploit.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New EU User Stats Could Reclassify Major Adult Sites Under DSA

Three high-traffic adult sites previously classified as “very large online platforms” under the European Union’s Digital Services Act are reporting user numbers below the threshold for that label, opening the way for possible downgrading of their obligations under that law.

Spicerack Launches 'SpicyFanz' Creator Monetization Platform

Adult product marketplace Spicerack Market has launched its SpicyFanz creator monetization platform.

Singapore Livestreamer Jailed for Performing 'Obscene Acts' in Public

A judge in Singapore on Thursday sentenced a Vietnamese woman to three weeks in jail for livestreaming “obscene acts” from a public area.

FSC Withdraws Support for North Dakota AV Bill

The Free Speech Coalition (FSC) has withdrawn its support for an age verification bill in North Dakota, following changes made by the state legislature.

APClips Launches New Blog

APClips has launched a blog, AmateurPorn.com.

Centrobill Launches 'Max' Payment Suite

Payment processing service Centrobill has launched its new Max Suite toolkit.

AEBN Publishes Popular Searches by Country for December, January

AEBN has released the list of popular searches from its straight and gay theaters by country in December and January.

South Dakota Legislators Debate AV Legal Strategies

The South Dakota state Senate Judiciary Committee on Tuesday heard testimony and debate over two competing age verification bills, in a hearing that focused largely on which piece of legislation could best withstand potential legal challenges.

Mobile OnlyFans Management Platform 'TopCreator' Launches

Mobile OnlyFans management and chat platform TopCreator has launched.

JustFor.fans Marks Its 7th Anniversary With Palm Springs Conference

JustFor.fans is celebrating its seventh anniversary with a four-day conference and party in Palm Springs May 18-21.

Show More