Close Menu

    Subscribe to Updates

    What's Hot

    Altcoin ETF summer in limbo as SEC hits pause on DOGE, HBAR, and AVAX filings

    June 13, 2025

    Tencent reopens talks to acquire South Korea’s Nexon, a game developer exploring blockchain

    June 13, 2025

    XRP targets $5 but Little Pepe presale steals the spotlight as it raises $200,000 on day 1

    June 13, 2025
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Crypto scammers use fake job interviews to enable backdoor malware attacks
    Crypto

    Crypto scammers use fake job interviews to enable backdoor malware attacks

    John SmithBy John SmithDecember 30, 2024No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A sophisticated attack is targeting web3 professionals, tricking them into running malicious code on their systems during fake interviews as part of a lucrative offer from crypto scammers disguised as recruiters.

    On Dec. 28, on-chain investigator Taylor Monahan flagged a new scheme being leveraged by bad actors who claim to be recruiters for prominent crypto firms to approach targets with lucrative job offers on platforms like LinkedIn, freelancing platforms, Telegram, etc.

    Once the victim is interested, they are redirected to a video interviewing platform dubbed “Willo | Video Interviewing,” which isn’t malicious in itself but is designed to make the entire scheme look convincing to the victims.

    As part of the process, victims are initially asked standard industry-related questions, such as their views on significant crypto trends over the next 12 months. These questions help build trust and make the interaction seem legitimate. 

    However, the real attack unfolds during the final question, which requires recording it on video. When trying to set up the video recording process, victims encounter a technical issue with their microphone or camera.

    This is when the real attack plays out, as the website presents malicious troubleshooting steps masked as a solution to the issue. 

    According to Monahan, if a user follows the steps, which in some cases involve executing system-level commands depending on their operating systems, it grants attackers backdoor access to their devices.

    Crypto scammers use fake job interviews to enable backdoor malware attacks - 1
    A troubleshooting guide presented to victims to fix a supposed technical glitch | Source: Taylor Monahan on X

    “It allows them to do anything on your device. It’s not really general purpose stealer, it’s general purpose access. Ultimately they’ll rekt you via whatever means are required,” Monahan wrote.

    This access could potentially allow malicious actors to bypass security measures, install malware, monitor activities, steal sensitive data, or drain cryptocurrency wallets without the victim’s knowledge, based on typical outcomes observed in similar attacks.

    Monahan advised crypto users to avoid running unfamiliar code and recommended those who may have been exposed to such attacks wipe their devices entirely to prevent further compromise.

    The attack deviates from the usual tactics seen in similar job recruitment scams. For instance, cybersecurity firm Cado Security Labs, earlier this month, uncovered a scheme involving a fake meeting application that injected malware, enabling attackers to drain cryptocurrency wallets and steal browser-stored credentials.

    Similarly, last year, crypto.news reported an incident where scam recruiters targeted blockchain developers on Upwork, instructing them to download and debug malicious npm packages hosted on a GitHub repository. Once executed, these packages deployed scripts granting attackers remote access to victims’ devices.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Altcoin ETF summer in limbo as SEC hits pause on DOGE, HBAR, and AVAX filings

    June 13, 2025

    Tencent reopens talks to acquire South Korea’s Nexon, a game developer exploring blockchain

    June 13, 2025

    XRP targets $5 but Little Pepe presale steals the spotlight as it raises $200,000 on day 1

    June 13, 2025
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Altcoin ETF summer in limbo as SEC hits pause on DOGE, HBAR, and AVAX filings

    By John SmithJune 13, 20250

    The U.S. Securities and Exchange Commission (SEC) has hit the pause button on several crypto…

    Tencent reopens talks to acquire South Korea’s Nexon, a game developer exploring blockchain

    June 13, 2025

    XRP targets $5 but Little Pepe presale steals the spotlight as it raises $200,000 on day 1

    June 13, 2025

    Shopify to pilot USDC payments via Coinbase and Stripe

    June 13, 2025

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (569)
    • Bitcoin (27)
    • Blockchain (136)
    • Crypto (8,623)
    • Ethereum (623)
    • Lithosphere News Releases (144)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.