New Trojan Targets Monster.com Users for Identity Theft

CUPERTINO, Calif. — Online job hunters using the Internet to seek out a new career direction should take added precautions if posting information to Monster.com is part of their strategy, according to information uncovered by security software vendor Symantec this week.

Symantec’s researchers have identified a new Trojan being employed to target users of Monster.com for identity theft, according to the company’s security response blog.

The Trojan in question has been dubbed Infostealer.Monstres, and although the exploit has been characterized by Symantec as “very low” risk, the amount of data already collected by the attackers behind the Trojan already is prodigious.

During their investigation, Symantec’s researchers noticed that the Trojan was uploading data to a remote server. When the team accessed the remote server, they found “over 1.6 million entries with personal information belonging to several hundred thousand people,” according to a post made to the security response blog by Symantec’s Amado Hidalgo.

Surprised that such a low-profile Trojan was used to attack so many people, the Symantec team dug around to discover how the data was obtained.

After discovering that connections were only being made to the sub-domains hiring.monster.com and recruiter.monster.com, the researchers concluded that the Trojan “appears to be using the (probably stolen) credentials of a number of recruiters to login to the website and perform searches for resumes of candidates located in certain countries or working in certain fields.”

According to Symantec, the Trojan functions by sending HTTP commands that navigate the Managed Folders section of the site. The Trojan then parses the output from a pop-up window that contains the profiles of the candidates that match the compromised recruiters’ saved searches.

Symantec’s researchers found that a wide range of personal details of the job candidates have been accessed, and then uploaded to the remote server that is controlled by the attackers. The personal details include the name, surname, email address, country, home address, work/mobile/home phone numbers and resume ID, according to the security response blog.

“Such a large database of highly personal information is a spammer’s dream,” Hidalgo wrote. “In fact, we found the Trojan can be instructed to send spam email using a mail template downloadable from the command & control server.”

Symantec has informed Monster.com of the compromised recruiter accounts so that the accounts can be disabled, Hidalgo said. Symantec also suggested that to reduce the risk of identity theft, users should limit the contact information they post on job-hunting sites, and never disclose information such as Social Security numbers, passport or driver’s license numbers, bank account information or other sensitive details.

For more information on the Infostealer.Monstres Trojan, see the Symantec advisory concerning the exploit.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2026 XBIZ Amsterdam Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Amsterdam, set to take place Sept. 10-13 at Passenger Terminal Amsterdam.

Ukrainian Legislators Revive Porn Decriminalization Push

The Verkhovna Rada, Ukraine’s parliament, is once again considering a bill that would decriminalize the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

Ofcom Fines XGroovy $986,000 for AV Noncompliance

U.K. media regulator Ofcom on Thursday imposed a fine of 700,000 pounds (about $986,000) against adult website XGroovy for failing to comply with provisions of the Online Safety Act.

Segpay Opens New Global Headquarters in Boca Raton

Segpay has selected Boca Raton for its new global headquarters.

X3 Euro All-Stars Paint Amsterdam Red in Billboard Campaign

The X3 Expo Euro All-Stars are making a splash on the vibrant streets of Amsterdam as the creator-first fan event prepares to make its debut on the continent.

Tiny Secret Games Taps Pauline Schmiechen for Growth and Partnerships Advisor

Adult game studio Tiny Secret Games has named Pauline Schmiechen as its new growth and partnerships advisor.

BranditScan Names Aerie Saunders as Community Manager

BranditScan has named Aerie Saunders as its new community manager.

'Goddess' Charlotte Sins Blesses the September Issue of X3 Magazine

Charlotte Sins graces the cover of the September issue of X3 magazine, the premier publication capturing the real personalities, passions, and stories behind top stars.

Centrobill Names Len Garcia as Chief Sales Officer

Centrobill has named Len Garcia as its new chief sales officer.

Mistrezz.AI Joins ASACP as Corporate Sponsor

The UK-based adult AI companion platform Mistrezz.AI has signed on as the latest corporate sponsor for Association of Sites Advocating Child Protection (ASACP).

Show More