New Trojan Targets Monster.com Users for Identity Theft

CUPERTINO, Calif. — Online job hunters using the Internet to seek out a new career direction should take added precautions if posting information to Monster.com is part of their strategy, according to information uncovered by security software vendor Symantec this week.

Symantec’s researchers have identified a new Trojan being employed to target users of Monster.com for identity theft, according to the company’s security response blog.

The Trojan in question has been dubbed Infostealer.Monstres, and although the exploit has been characterized by Symantec as “very low” risk, the amount of data already collected by the attackers behind the Trojan already is prodigious.

During their investigation, Symantec’s researchers noticed that the Trojan was uploading data to a remote server. When the team accessed the remote server, they found “over 1.6 million entries with personal information belonging to several hundred thousand people,” according to a post made to the security response blog by Symantec’s Amado Hidalgo.

Surprised that such a low-profile Trojan was used to attack so many people, the Symantec team dug around to discover how the data was obtained.

After discovering that connections were only being made to the sub-domains hiring.monster.com and recruiter.monster.com, the researchers concluded that the Trojan “appears to be using the (probably stolen) credentials of a number of recruiters to login to the website and perform searches for resumes of candidates located in certain countries or working in certain fields.”

According to Symantec, the Trojan functions by sending HTTP commands that navigate the Managed Folders section of the site. The Trojan then parses the output from a pop-up window that contains the profiles of the candidates that match the compromised recruiters’ saved searches.

Symantec’s researchers found that a wide range of personal details of the job candidates have been accessed, and then uploaded to the remote server that is controlled by the attackers. The personal details include the name, surname, email address, country, home address, work/mobile/home phone numbers and resume ID, according to the security response blog.

“Such a large database of highly personal information is a spammer’s dream,” Hidalgo wrote. “In fact, we found the Trojan can be instructed to send spam email using a mail template downloadable from the command & control server.”

Symantec has informed Monster.com of the compromised recruiter accounts so that the accounts can be disabled, Hidalgo said. Symantec also suggested that to reduce the risk of identity theft, users should limit the contact information they post on job-hunting sites, and never disclose information such as Social Security numbers, passport or driver’s license numbers, bank account information or other sensitive details.

For more information on the Infostealer.Monstres Trojan, see the Symantec advisory concerning the exploit.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2026 XBIZ Miami Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Miami, set to take place May 11-14 at the Goodtime Hotel in South Beach.

UPDATED: Utah VPN Rule Enforcement Paused in Aylo Lawsuit

Provisions of a new Utah law making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification, which were set to come into force on Wednesday, have been put on hold until Sept. 3.

JustFor.fans Launches 'JFF Create' iPhone App

JustFor.fans (JFF) has launched its new iPhone creator management app, JFF Create.

ShootXEvents Joins ASACP as Media Sponsor

ShootXEvents has signed on as an in-kind media sponsor for the Association of Sites Advocating Child Protection (ASACP).

Pornhub Unblocks UK Users on iOS Devices, Citing Apple AV Effectiveness

Pornhub parent company Aylo on Tuesday announced that users in the United Kingdom will once again be able to access the popular site if they are using Apple devices and have confirmed their age through Apple’s U.K. age-verification process.

FSC Launches 'Know Your Rights' 1st Amendment Resource Page

The Free Speech Coalition (FSC) has launched "Know Your Rights," a resource page detailing First Amendment protest guidelines.

Utah VPN Rule for Adult Sites Takes Effect This Week

A new law in Utah comes into force Wednesday, making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification.

UPDATED: Court Approves Class Action in Labor Claims Against VMG

A U.S. district court has granted class certification in a civil lawsuit filed against Vixen Media Group (VMG) by retired performer Kenzie Anne, making it possible for additional performers to join in a class action against the company.

Brazil Invites Public Input on Guidelines for New Digital Law

Brazil’s National Data Protection Authority (ANPD) is soliciting public comments to help improve interpretation and application of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

X3 Expo Unveils Euro All-Stars for Inaugural Amsterdam Edition

X3 Expo, Hollywood's premier adult entertainment expo, makes its European debut at Passenger Terminal Amsterdam Sept. 11-12, bringing together fans, creators, and industry insiders for the Continent’s largest assembly of adult entertainment stars, alongside a dazzling lineup of attractions spotlighting the cutting edge of modern media and pleasure tech.

Show More