Scammers posing as recruiters for cryptocurrency companies have defrauded victims of $11.8 million (S$15.1 million) by exploiting fake job offers to compromise their employers' systems. According to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore, the scheme begins with a bogus recruiter contacting individuals on LinkedIn. The conversation then moves to email, using a spoofed domain that closely mimics a legitimate firm's, and interviews are conducted via Google Meet with the interviewer keeping their camera off.
Victims are subsequently directed to a fake website to complete a technical coding assessment, often on a company-issued device. During this process, they unknowingly download malicious software. This malware captures a session token, which is used to bypass multi-factor authentication and gain access to the victim's Bitbucket account, a platform used for storing and managing source code. Once inside, attackers can alter software systems, access internal servers, and obtain credentials. These credentials are then used to circumvent transaction limits and approval processes, ultimately leading to the theft of funds.
Researchers have documented similar operations, such as 'Contagious Interviews,' where fake recruiters target Web3 developers with malicious code, including compromised packages uploaded to the npm registry. While some campaigns are attributed to North Korean hackers, the tactics are not exclusive to them. The Russian-speaking group Crazy Evil, for instance, created a fake Web3 company, ChainSeeker.io, to lure applicants into installing malware. The advisory did not name any specific companies targeted or disclose where the stolen funds were transferred.