Fake recruiter sends trojan disguised as an anti-bot terminal check
A developer received a recruiting email from a fake Taiko recruiter asking him to paste a command into his terminal to "verify I'm not a bot." The downloaded verify_m script (49,916 bytes) drops a base64 second stage, reports to gaganata.ink C2 endpoints and self-deletes; as of October 9 the trojan is still served with HTTP 200.
- The taikotalent.xyz domain was registered on September 27, eight days before the email
- Emails passed SPF and DKIM via Resend and Amazon SES in sa-east-1
- The verify_m script is 49,916 bytes and self-deletes after execution
- C2 domains api.gaganata.ink and api.fallgganata.ink return 404
Read next
Security