Eilmeldung
FRIncendie aux Hautes Fagnes : Évacuations en cours dans l'est de la BelgiqueESTerremoto en Granada: más de 40 movimientos sísmicos en 24 horas y tormentas intensasTRİran ve ABD Arasında Tansiyon Yükseldi: Hürmüz Boğazı'nda Saldırı ve İsrail'in Lübnan'a SaldırısıRUMoroccan Police Use Force Against Migrants at Ceuta BorderCN菲國防部長鐵歐多洛駁斥中國指控 批為烏賊戰術KRSouth Korea's chief trade negotiator dismissed amid U.S. tariff pressureINTLIsraeli airstrikes on southern Lebanon kill 11, including three childrenFRTrump écarte les inquiétudes sur les conditions de vie à bord de l'USS Abraham LincolnESGranada sufre un terremoto de magnitud 5 con daños materiales y pánico entre la poblaciónTRKuzey Kore, ABD ve Güney Kore'nin Tatbikatına Karşı Ateşli Bir Zirve Açıklaması YaptıFRIncendie aux Hautes Fagnes : Évacuations en cours dans l'est de la BelgiqueESTerremoto en Granada: más de 40 movimientos sísmicos en 24 horas y tormentas intensasTRİran ve ABD Arasında Tansiyon Yükseldi: Hürmüz Boğazı'nda Saldırı ve İsrail'in Lübnan'a SaldırısıRUMoroccan Police Use Force Against Migrants at Ceuta BorderCN菲國防部長鐵歐多洛駁斥中國指控 批為烏賊戰術KRSouth Korea's chief trade negotiator dismissed amid U.S. tariff pressureINTLIsraeli airstrikes on southern Lebanon kill 11, including three childrenFRTrump écarte les inquiétudes sur les conditions de vie à bord de l'USS Abraham LincolnESGranada sufre un terremoto de magnitud 5 con daños materiales y pánico entre la poblaciónTRKuzey Kore, ABD ve Güney Kore'nin Tatbikatına Karşı Ateşli Bir Zirve Açıklaması Yaptı
Newsgather
ZurückCrypto Job Scam Siphons $11.8M Via Malicious Coding Tests
Crypto Job Scam Siphons $11.8M Via Malicious Coding Tests
In Entwicklung
Decryptvor 7 StundenCybersecurity2 Min. Lesezeit

Crypto Job Scam Siphons $11.8M Via Malicious Coding Tests

Singapore agencies warn of fake crypto recruiter scams bypassing MFA to breach corporate systems and steal millions.

Auf einen Blick

Scammers posing as crypto recruiters stole $11.8 million using fake job offers and technical assessments that installed malware on targets' devices, bypassing multi-factor authentication to drain corporate funds, Singapore authorities warn.

KI-generierte Zusammenfassung

Warum es wichtig ist

Scammers use fake recruiter profiles and technical tests to deploy malware and breach corporate systems.

Schriftgröße

Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets' employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore.

Setting out how the scam works in a statement on Friday, reported by The Straits Times and Channel NewsAsia, the agencies said a victim was approached on LinkedIn by someone posing as a recruiter for a crypto company, then moved to email, where the sender used a spoofed domain closely resembling a real firm's. Several interviews followed on Google Meet. The interviewer kept their camera off throughout.

The victim was then sent to a spoofed website to complete a technical coding assessment, and did so on a company-issued device, downloading malicious software in the process without realizing it.

The malware captured a session token, the string a service issues to keep a user logged in. Because the token represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages its source code.

From there the attackers altered the employer's software systems and reached its internal servers, the agencies said, collecting credentials that were then used to get around transaction limits and approval checks and move funds. The advisory does not name any company, say where the funds went, or attribute the attacks to anyone. Decrypt has approached LinkedIn for comment and will update this article should they respond.

That pattern is well documented, with researchers tracking a long-running operation they call Contagious Interview, in which fake recruiters steer Web3 developers toward malicious code, including more than 300 booby-trapped packages uploaded to the npm registry. A group known as TraderTraitor has used fake job offers to reach corporate cloud systems rather than individual wallets, which one researcher put down to that being where the money sits. Others have posed as recruiters from Coinbase and Uniswap to get targets running commands.

Those campaigns are attributed to North Korean hackers, but the playbook is not uniquely theirs. The Russian-speaking crew Crazy Evil built an entire fake Web3 company, ChainSeeker.io, and advertised blockchain analyst roles to lure applicants into installing wallet-draining malware.

Singapore agencies’ advice to individuals is to verify recruiters through official channels, treat an interviewer who will not turn on their camera as a warning sign, and never run code from an unverified source. For companies, the agencies recommend securing API keys and internal credentials, strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity. Where a compromise is suspected, they advise isolating affected systems, revoking active sessions, resetting credentials and reviewing access logs.

Worauf zu achten ist

KI-Ausblick — Möglichkeiten, keine Fakten

  • Decrypt will update the article if LinkedIn responds to requests for comment.

    Möglich · Innerhalb von Tagen

Offene Fragen

  • Which specific companies were targeted in Singapore?
  • Where were the stolen funds transferred?

Verwandte Themen

This article was originally published by Decrypt.

Ähnliche Meldungen

Bitcoin Self-Custody Risks, ETF Inflows, and Corporate Crypto Strategies Under Scrutiny
Business·vor 6 Stunden

Bitcoin Self-Custody Risks, ETF Inflows, and Corporate Crypto Strategies Under Scrutiny

A recent $116 million hardware wallet exploit reignites the debate on self-custody risks versus institutional investment vehicles like Bitcoin ETFs, which saw their strongest inflows since April. Meanwhile, Strategy plans to resume Bitcoin accumulation, Riot Platforms secures a $9 billion AI compute deal, and Trump Media revamps its crypto treasury strategy after a $238 million Q2 loss.

Cointelegraph
5 Min. Lesezeit
Mehr zu diesem Themacrypto scam